Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-09670

Опубликовано: 24 сент. 2025
Источник: fstec
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

Уязвимость веб-сервера Undertow связана с неограниченным распределением ресурсов. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

Red Hat Inc.

Наименование ПО

Red Hat Single Sign-On
Data Grid
Red Hat Process Automation
Red Hat Data Grid
Red Hat JBoss Enterprise Application Platform Expansion Pack
Red Hat JBoss Enterprise Application Platform
Red Hat Fuse
Red Hat build of Apache Camel for Spring Boot
undertow
JBoss Enterprise Application Platform

Версия ПО

7 (Red Hat Single Sign-On)
8 (Data Grid)
7 (Red Hat Process Automation)
8 (Red Hat Data Grid)
- (Red Hat JBoss Enterprise Application Platform Expansion Pack)
7 (Red Hat JBoss Enterprise Application Platform)
7 (Red Hat Fuse)
4 (Red Hat build of Apache Camel for Spring Boot)
до 2.3.19.Final (undertow)
до 2.2.38.Final (undertow)
8.1 (JBoss Enterprise Application Platform)
7.1 EUS for RHEL 7 (JBoss Enterprise Application Platform)
7.3 EUS for RHEL 7 (JBoss Enterprise Application Platform)
8.0 for RHEL 8 (JBoss Enterprise Application Platform)
8.0 for RHEL 9 (JBoss Enterprise Application Platform)
до 1.4.18.SP18 (undertow)
до 2.0.41.SP9 (undertow)
3.5.8 (Red Hat build of Apache Camel for Spring Boot)
- (JBoss Enterprise Application Platform)
7.4 ELS on RHEL 7 (JBoss Enterprise Application Platform)
7.4 ELS on RHEL 8 (JBoss Enterprise Application Platform)
7.4 ELS on RHEL 9 (JBoss Enterprise Application Platform)
8.0 (JBoss Enterprise Application Platform)
8.1 for RHEL 8 (JBoss Enterprise Application Platform)
8.1 for RHEL 9 (JBoss Enterprise Application Platform)

Тип ПО

Сетевое программное средство
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,8)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,5)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
Для Undertow:
https://issues.redhat.com/browse/UNDERTOW-2598
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2025-9784

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 80%
0.0217
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 месяцев назад

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

CVSS3: 7.5
redhat
11 месяцев назад

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

CVSS3: 7.5
nvd
11 месяцев назад

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

CVSS3: 7.5
debian
11 месяцев назад

A flaw was found in Undertow where malformed client requests can trigg ...

CVSS3: 7.5
github
11 месяцев назад

Undertow MadeYouReset HTTP/2 DDoS Vulnerability

EPSS

Процентиль: 80%
0.0217
Низкий

7.5 High

CVSS3

7.8 High

CVSS2