CVE-2019-10212: Netapp Active Iq Unified Manager

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.

Affected products

  • Netapp Active Iq Unified Manager: affected versions not specified
  • Red Hat JBoss Data Grid: from 7.0.0, up to and including 7.3; affected versions not specified
  • Red Hat JBoss Enterprise Application Platform: affected versions not specified; version 7.2 only; version 7.3 only; version 7.4 only
  • Red Hat JBoss Fuse: from 7.0.0, up to and including 7.4
  • Red Hat Openshift Application Runtimes: affected versions not specified
  • Red Hat Single Sign-On: from 7.0, up to and including 7.3
  • Red Hat Undertow: before 2.0.20 (fixed in 2.0.20)

Published 2019-10-02. Last modified 2026-06-17.