CVE-2019-19343: Netapp Active Iq Unified Manager

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.

Affected products

  • Netapp Active Iq Unified Manager: affected versions not specified
  • Red Hat JBoss-Remoting: before 5.0.14 (fixed in 5.0.14); version 5.0.14 only
  • Red Hat JBoss Enterprise Application Platform: before 7.2.4 (fixed in 7.2.4)
  • Red Hat Undertow: before 2.0.25 (fixed in 2.0.25); version 2.0.25 only

Published 2021-03-23. Last modified 2026-06-17.