VYPR
High severity7.5NVD Advisory· Published Aug 31, 2022· Updated Jun 17, 2026

CVE-2022-1319

CVE-2022-1319

Description

A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

19
  • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 2 more
    • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
    • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
    • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
  • cpe:2.3:a:netapp:cloud_secure_agent:-:*:*:*:*:*:*:*
  • cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
  • cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
  • Red Hat/Undertow7 versions
    cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*range: <2.2.17
    • cpe:2.3:a:redhat:undertow:2.2.17:-:*:*:*:*:*:*
    • cpe:2.3:a:redhat:undertow:2.2.17:sp1:*:*:*:*:*:*
    • cpe:2.3:a:redhat:undertow:2.2.17:sp2:*:*:*:*:*:*
    • cpe:2.3:a:redhat:undertow:2.2.19:-:*:*:*:*:*:*
    • cpe:2.3:a:redhat:undertow:2.2.19:sp1:*:*:*:*:*:*
    • cpe:2.3:a:redhat:undertow:2.3.0:alpha1:*:*:*:*:*:*
  • Undertow/Undertowdescription
  • JBoss/EAPllm-create

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.