CVE-2019-3888: Netapp Active Iq Unified Manager

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)

Affected products

  • Netapp Active Iq Unified Manager: affected versions not specified
  • Red Hat JBoss Data Grid: affected versions not specified
  • Red Hat Openshift Application Runtimes: affected versions not specified
  • Red Hat Undertow: before 2.0.21 (fixed in 2.0.21)
  • Red Hat Virtualization: version 4.0 only
  • Red Hat Virtualization Host: version 4.0 only

Published 2019-06-12. Last modified 2026-06-17.