CVE-2019-19343: Netapp Active Iq Unified Manager
High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.
A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.
Affected products
- Netapp Active Iq Unified Manager: affected versions not specified
- Red Hat JBoss-Remoting: before 5.0.14 (fixed in 5.0.14); version 5.0.14 only
- Red Hat JBoss Enterprise Application Platform: before 7.2.4 (fixed in 7.2.4)
- Red Hat Undertow: before 2.0.25 (fixed in 2.0.25); version 2.0.25 only
Published 2021-03-23. Last modified 2026-06-17.