« Volver al listado

CVE-2021-3597

Estado: ModificadaMedia (5.9)—

A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (8)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-3597",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "undertow",
          "versions": [
            {
              "status": "affected",
              "version": "undertow 2.0.35.SP1, undertow 2.2.6.SP1, undertow 2.2.7.SP1, undertow 2.0.36.SP1, undertow 2.2.9.Final, undertow 2.0.39.Final"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-05-24T19:15:09.037",
  "references": [
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1970930",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20220804-0003/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1970930",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20220804-0003/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final."
    },
    {
      "lang": "es",
      "value": "Se ha encontrado un fallo en Undertow. El HTTP2SourceChannel no escribe la última trama en algunas circunstancias, resultando en una denegación de servicio. La mayor amenaza de esta vulnerabilidad es la disponibilidad. Este fallo afecta a Undertow versiones anteriores a 2.0.35.SP1, anteriores a 2.2.6.SP1, anteriores a 2.2.7.SP1, anteriores a 2.0.36.SP1, anteriores a 2.2.9.Final y anteriores a 2.0.39.Final"
    }
  ],
  "lastModified": "2026-06-17T04:05:24.497",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:fuse:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "077732DB-F5F3-4E9C-9AC0-8142AB85B32F"
            },
            {
              "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8423D7F-3A8F-4AD8-BF51-245C9D8DD816"
            },
            {
              "criteria": "cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:text-only:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADB40F59-CAAE-47D6-850C-12619D8D5B34"
            },
            {
              "criteria": "cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "341E6313-20D5-44CB-9719-B20585DC5AD6"
            },
            {
              "criteria": "cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BAD876A-2A44-4217-AD8E-723F6C659D6B",
              "versionEndExcluding": "2.0.35"
            },
            {
              "criteria": "cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9364241-A687-4277-BD0A-23875980F7BA",
              "versionEndExcluding": "2.2.6",
              "versionStartIncluding": "2.2.0"
            },
            {
              "criteria": "cpe:2.3:a:redhat:undertow:2.0.35:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1606D630-BD33-4D6C-AB09-E21567B9DAD7"
            },
            {
              "criteria": "cpe:2.3:a:redhat:undertow:2.0.36:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F6461F3-EE16-4F87-BB63-BF76458B7B57"
            },
            {
              "criteria": "cpe:2.3:a:redhat:undertow:2.0.39:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "600AB6B3-6091-49DF-AA7D-E4400F69D61F"
            },
            {
              "criteria": "cpe:2.3:a:redhat:undertow:2.2.6:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA47D051-72D8-4AA8-90FA-04B8CA1C9FE5"
            },
            {
              "criteria": "cpe:2.3:a:redhat:undertow:2.2.7:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BEC107E-11EE-497D-834C-CCF5921C0CE1"
            },
            {
              "criteria": "cpe:2.3:a:redhat:undertow:2.2.9:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1530774-1A8C-46D0-85BE-AC1A9CA0071E"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4911A72-5FAE-47C5-A141-2E3CA8E1CCAB"
            },
            {
              "criteria": "cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "645A908C-18C2-4AB1-ACE7-3969E3A552A5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2F6AB192-9D7D-4A9A-8995-E53A9DE9EAFC"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "142AD0DD-4CF3-4D74-9442-459CE3347E3A"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F4CFF558-3C47-480D-A2F0-BABF26042943"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3E0B672-3E06-4422-B2A4-0BD073AEC2A1"
            },
            {
              "criteria": "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A756737-1CC4-42C2-A4DF-E1C893B4E2D5"
            },
            {
              "criteria": "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B55E8D50-99B4-47EC-86F9-699B67D473CE"
            },
            {
              "criteria": "cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1BE6C1F-2565-4E97-92AA-16563E5660A5"
            },
            {
              "criteria": "cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5735E553-9731-4AAC-BCFF-989377F817B3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}