CVE-2019-3888: Netapp Active Iq Unified Manager
Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)
Affected products
- Netapp Active Iq Unified Manager: affected versions not specified
- Red Hat JBoss Data Grid: affected versions not specified
- Red Hat Openshift Application Runtimes: affected versions not specified
- Red Hat Undertow: before 2.0.21 (fixed in 2.0.21)
- Red Hat Virtualization: version 4.0 only
- Red Hat Virtualization Host: version 4.0 only
Published 2019-06-12. Last modified 2026-06-17.