{
  "threat_severity" : "Important",
  "public_date" : "2021-01-25T00:00:00Z",
  "bugzilla" : {
    "description" : "undertow: special character in query results in server errors",
    "id" : "1901304",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1901304"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-400",
  "details" : [ "A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.", "A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Fuse 7.10",
    "release_date" : "2021-12-14T00:00:00Z",
    "advisory" : "RHSA-2021:5134",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7",
    "package" : "undertow",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat Integration",
    "release_date" : "2021-08-18T00:00:00Z",
    "advisory" : "RHSA-2021:3205",
    "cpe" : "cpe:/a:redhat:integration:1",
    "package" : "undertow"
  }, {
    "product_name" : "Red Hat Integration Camel Quarkus 2",
    "release_date" : "2021-08-18T00:00:00Z",
    "advisory" : "RHSA-2021:3207",
    "cpe" : "cpe:/a:redhat:camel_quarkus:2"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0250",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3",
    "package" : "undertow-core"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9582",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-glassfish-el-0:3.0.1-4.b08_redhat_00005.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9582",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-hibernate-0:5.1.17-3.Final_redhat_00004.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9582",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-jackson-databind-0:2.8.11.6-3.SP1_redhat_00003.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9582",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-jboss-ejb-client-0:4.0.12-1.Final_redhat_00002.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9582",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-netty-0:4.1.63-2.Final_redhat_00003.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9582",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-undertow-0:1.4.18-16.SP14_redhat_00001.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9582",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-wildfly-0:7.1.11-4.GA_redhat_00002.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9582",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-wildfly-elytron-0:1.1.14-1.Final_redhat_00001.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9582",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-wildfly-http-client-0:1.0.21-1.Final_redhat_00001.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9582",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-wildfly-naming-client-0:1.0.13-1.Final_redhat_00001.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9582",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-wildfly-openssl-0:1.0.12-1.Final_redhat_00001.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2025-06-25T00:00:00Z",
    "advisory" : "RHSA-2025:9582",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-wildfly-openssl-linux-0:1.0.12-6.Final_redhat_00001.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-activemq-artemis-0:2.9.0-7.redhat_00017.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-glassfish-jsf-0:2.3.9-12.SP13_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-hal-console-0:3.2.12-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-hibernate-0:5.3.20-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-httpcomponents-client-0:4.5.13-1.redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jboss-ejb-client-0:4.0.37-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jboss-genericjms-0:2.0.8-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jboss-modules-0:1.11.0-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jboss-remoting-0:5.0.20-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jboss-server-migration-0:1.7.2-4.Final_redhat_00005.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jboss-xnio-base-0:3.7.12-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-narayana-0:5.9.10-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-opentracing-interceptors-0:0.0.4.1-2.redhat_00002.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-resteasy-0:3.11.3-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-undertow-0:2.0.33-1.SP2_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-wildfly-0:7.3.5-2.GA_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-wildfly-discovery-0:1.2.1-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-wildfly-elytron-0:1.10.10-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0246",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-wildfly-http-client-0:1.0.24-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-activemq-artemis-0:2.9.0-7.redhat_00017.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-glassfish-jsf-0:2.3.9-12.SP13_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-hal-console-0:3.2.12-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-hibernate-0:5.3.20-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-httpcomponents-client-0:4.5.13-1.redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jboss-ejb-client-0:4.0.37-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jboss-genericjms-0:2.0.8-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jboss-modules-0:1.11.0-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jboss-remoting-0:5.0.20-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jboss-server-migration-0:1.7.2-4.Final_redhat_00005.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jboss-xnio-base-0:3.7.12-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-narayana-0:5.9.10-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-opentracing-interceptors-0:0.0.4.1-2.redhat_00002.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-resteasy-0:3.11.3-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-undertow-0:2.0.33-1.SP2_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-wildfly-0:7.3.5-2.GA_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-wildfly-discovery-0:1.2.1-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-wildfly-elytron-0:1.10.10-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0247",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-wildfly-http-client-0:1.0.24-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-activemq-artemis-0:2.9.0-7.redhat_00017.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-glassfish-jsf-0:2.3.9-12.SP13_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-hal-console-0:3.2.12-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-hibernate-0:5.3.20-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-httpcomponents-client-0:4.5.13-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jboss-ejb-client-0:4.0.37-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jboss-genericjms-0:2.0.8-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jboss-modules-0:1.11.0-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jboss-remoting-0:5.0.20-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jboss-server-migration-0:1.7.2-4.Final_redhat_00005.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jboss-xnio-base-0:3.7.12-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-narayana-0:5.9.10-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-opentracing-interceptors-0:0.0.4.1-2.redhat_00002.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-resteasy-0:3.11.3-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-undertow-0:2.0.33-1.SP2_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-wildfly-0:7.3.5-2.GA_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-wildfly-discovery-0:1.2.1-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-wildfly-elytron-0:1.10.10-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2021-01-25T00:00:00Z",
    "advisory" : "RHSA-2021:0248",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-wildfly-http-client-0:1.0.24-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat Single Sign-On 7.4.5",
    "release_date" : "2021-02-01T00:00:00Z",
    "advisory" : "RHSA-2021:0327",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7",
    "package" : "undertow"
  }, {
    "product_name" : "Red Hat support for Spring Boot 2.3.10",
    "release_date" : "2021-09-09T00:00:00Z",
    "advisory" : "RHSA-2021:3425",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0",
    "package" : "undertow"
  }, {
    "product_name" : "Text-Only RHOAR",
    "release_date" : "2021-02-08T00:00:00Z",
    "advisory" : "RHSA-2021:0295",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat build of Quarkus",
    "fix_state" : "Not affected",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0"
  }, {
    "product_name" : "Red Hat Decision Manager 7",
    "fix_state" : "Not affected",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_brms_platform:7"
  }, {
    "product_name" : "Red Hat Integration Camel K 1",
    "fix_state" : "Affected",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:integration:1",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat Integration Camel Quarkus 1",
    "fix_state" : "Affected",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:camel_quarkus:2",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat Integration Service Registry",
    "fix_state" : "Not affected",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:integration:1"
  }, {
    "product_name" : "Red Hat JBoss Data Grid 7",
    "fix_state" : "Out of support scope",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:7",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat JBoss Fuse 6",
    "fix_state" : "Affected",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:jboss_fuse:6",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat OpenShift Application Runtimes",
    "fix_state" : "Affected",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13 (Queens)",
    "fix_state" : "Will not fix",
    "package_name" : "opendaylight",
    "cpe" : "cpe:/a:redhat:openstack:13",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Process Automation 7",
    "fix_state" : "Not affected",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
  }, {
    "product_name" : "Red Hat support for Spring Boot",
    "fix_state" : "Affected",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0",
    "impact" : "low"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2020-27782\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-27782" ],
  "name" : "CVE-2020-27782",
  "mitigation" : {
    "value" : "The issue can be mitigated by using HTTP/1.1 instead of AJP to proxy to the back-end.",
    "lang" : "en:us"
  },
  "csaw" : false
}