Resource exhaustion in Apache Tomcat - CVE-2019-0199
Published: March 25, 2019 / Updated: January 20, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists within the HTTP/2 implementation in Apache Tomcat that accepts streams with excessive numbers of SETTINGS frames and also permits clients to keep streams open without reading/writing request/response data. A remote attacker can exhaust all available threads on the server and perform denial of service attack.
Affected software
JBoss Enterprise Web Server
Amazon Linux AMI
Opensuse
Fedora
Dell Support Assist Enterprise
Oracle Database Server
Instantis EnterpriseTrack
tomcat
How to mitigate CVE-2019-0199
Dell Support Assist Enterprise - update to 4.00.06.00
JBoss Enterprise Web Server - update to 5.2.0
tomcat - addressed in versions 9.0.21-1.fc29, 9.0.21-1.fc30
External References
Related Security Bulletins
- Denial of service in Apache Tomcat
- Amazon Linux AMI update for tomcat8
- OpenSUSE Linux update for tomcat
- OpenSUSE Linux update for tomcat
- OpenSUSE Linux update for tomcat
- Amazon Linux AMI update for tomcat8
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Multple vulnerabilities in Red Hat JBoss Web Server
- Multiple vulnerabilities in Oracle Database Server
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Fedora 29 update for tomcat
- Fedora 30 update for tomcat
- Multiple vulnerabilities in Instantis EnterpriseTrack