Vulnerability in Undertow AJP Listener affecting Red Hat Products
CVE-2026-15554
Key Information:
What is CVE-2026-15554?
The Undertow AJP listener improperly honors forged SSL_CERT and IS_SSL attributes without enforcing shared-secret authentication. This vulnerability allows unauthenticated attackers with TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate through the AJP protocol. Organizations using Undetow should review their configurations to enhance security and mitigate potential exploitation.
Affected Version(s)
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.16.0-22.redhat_00057.1.el7eap
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.3.14-11.SP11_redhat_00001.1.el7eap
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:1.5.26-2.Final_redhat_00001.1.el7eap