High severity7.5NVD Advisory· Published Aug 31, 2022· Updated Jun 17, 2026
CVE-2022-1319
CVE-2022-1319
Description
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
- cpe:2.3:a:netapp:cloud_secure_agent:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*range: <2.2.17
- cpe:2.3:a:redhat:undertow:2.2.17:-:*:*:*:*:*:*
- cpe:2.3:a:redhat:undertow:2.2.17:sp1:*:*:*:*:*:*
- cpe:2.3:a:redhat:undertow:2.2.17:sp2:*:*:*:*:*:*
- cpe:2.3:a:redhat:undertow:2.2.19:-:*:*:*:*:*:*
- cpe:2.3:a:redhat:undertow:2.2.19:sp1:*:*:*:*:*:*
- cpe:2.3:a:redhat:undertow:2.3.0:alpha1:*:*:*:*:*:*
- Undertow/Undertowdescription
Patches
Vulnerability mechanics
References
6- github.com/undertow-io/undertow/commit/1443a1a2bbb8e32e56788109d8285db250d55c8bnvdPatchThird Party Advisory
- github.com/undertow-io/undertow/commit/7c5b3ab885b5638fd3f1e8a935d5063d68aa2df3nvdPatchThird Party Advisory
- access.redhat.com/security/cve/CVE-2022-1319nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- issues.redhat.com/browse/UNDERTOW-2060nvdIssue TrackingVendor Advisory
- security.netapp.com/advisory/ntap-20221014-0006/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.