CVE-2020-10719: Netapp Active Iq Unified Manager

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

Affected products

  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Oncommand Insight: before 7.3.13 (fixed in 7.3.13)
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Red Hat Fuse: version 1.0 only
  • Red Hat JBoss Enterprise Application Platform: affected versions not specified; version 7.3 only; version 7.4 only; version 7.2 only
  • Red Hat Openshift Application Runtimes: affected versions not specified
  • Red Hat Single Sign-On: affected versions not specified
  • Red Hat Undertow: before 2.1.1 (fixed in 2.1.1)

Published 2020-05-26. Last modified 2026-06-17.