The vendor explicitly identifies these products as affected by this CVE.
- undertow-core as a component of Red Hat JBoss Enterprise Application Platform 7
- undertow-core as a component of Red Hat JBoss Enterprise Application Platform 8
- Summary
- the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol.
- Remediation
- Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
