CVE-2022-1259: High severity ibm watson knowledge catalog vulnerability
A flaw was found in Undertow where a potential security issue in flow control handling by browser over HTTP/2 may potentially cause overhead or DOS in the server. The highest impact of this vulnerability is availability.(incomplete fix for CVE-2021-3629)
Other sources
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server.
Undertow is vulnerable to a denial of service, caused by a potential security issue in flow control over HTTP/2. By sending a specially-crafted packet, a remote attacker could exploit this vulnerability to a denial of service.
— IBM
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-1259?
CVE-2022-1259 is a vulnerability in Undertow that may cause overhead or a denial of service in the server due to a potential security issue in flow control handling by the browser over HTTP/2.
How severe is CVE-2022-1259?
CVE-2022-1259 has a severity score of 7.5 (high).
How can the CVE-2022-1259 vulnerability be fixed?
To fix the CVE-2022-1259 vulnerability, update to version 2.2.19-1.SP2_redhat_00001.1.el8ea or higher for eap7-undertow.
Which software packages are affected by CVE-2022-1259?
CVE-2022-1259 affects eap7-undertow versions 2.2.17 up to and including 2.2.19, Redhat Jboss Enterprise Application Platform 7.0.0, and other related packages.
What is the Common Weakness Enumeration (CWE) for CVE-2022-1259?
The CWEs associated with CVE-2022-1259 are CWE-400: Uncontrolled Resource Consumption and CWE-770: Allocation of Resources Without Limits or Throttling.