CVE-2016-7046
published 2016-10-03CVE-2016-7046: Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial…
PriorityP426medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
2.48%
82.9th percentile
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 1.4.3-1 (forky) | undertow 1.4.3-1 (forky) |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | undertow | >= 0 < 1.4.3-1 | 1.4.3-1 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Undertow Uncaught Exception vulnerability
ghsa·2022-05-17
CVE-2016-7046 [MEDIUM] CWE-248 Undertow Uncaught Exception vulnerability
Undertow Uncaught Exception vulnerability
A long URL proxy request lead to java.nio.BufferOverflowException in Undertow.
OSV
Undertow Uncaught Exception vulnerability
osv·2022-05-17
CVE-2016-7046 [MEDIUM] Undertow Uncaught Exception vulnerability
Undertow Uncaught Exception vulnerability
A long URL proxy request lead to java.nio.BufferOverflowException in Undertow.
OSV
CVE-2016-7046: Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a
osv·2016-10-03·CVSS 5.9
CVE-2016-7046 [MEDIUM] CVE-2016-7046: Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
Red Hat
undertow: Long URL proxy request lead to java.nio.BufferOverflowException and DoS
vendor_redhat·2016-09-15·CVSS 5.9
CVE-2016-7046 [MEDIUM] CWE-119 undertow: Long URL proxy request lead to java.nio.BufferOverflowException and DoS
undertow: Long URL proxy request lead to java.nio.BufferOverflowException and DoS
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
It was discovered that a long URL sent to EAP 7 Server operating as a reverse proxy with default buffer sizes causes a Denial of Service.
Debian
CVE-2016-7046: undertow - Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a rever...
vendor_debian·2016·CVSS 5.9
CVE-2016-7046 [MEDIUM] CVE-2016-7046: undertow - Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a rever...
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
Scope: local
forky: resolved (fixed in 1.4.3-1)
sid: resolved (fixed in 1.4.3-1)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-2640.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2641.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2642.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2657.htmlhttp://www.securityfocus.com/bid/93173https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=1376646http://rhn.redhat.com/errata/RHSA-2016-2640.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2641.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2642.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2657.htmlhttp://www.securityfocus.com/bid/93173https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=1376646
2016-10-03
Published