Resource exhaustion in Apache Tomcat - CVE-2019-0199

 

Resource exhaustion in Apache Tomcat - CVE-2019-0199

Published: March 25, 2019 / Updated: January 20, 2020


Vulnerability identifier: #VU18067
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0199
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists within the HTTP/2 implementation in Apache Tomcat that accepts streams with excessive numbers of SETTINGS frames and also permits clients to keep streams open without reading/writing request/response data. A remote attacker can exhaust all available threads on the server and perform denial of service attack.


Affected software

Apache Tomcat
JBoss Enterprise Web Server
Amazon Linux AMI
Opensuse
Fedora
Dell Support Assist Enterprise
Oracle Database Server
Instantis EnterpriseTrack
tomcat

How to mitigate CVE-2019-0199

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.38, 9.0.16
Dell Support Assist Enterprise - update to 4.00.06.00
JBoss Enterprise Web Server - update to 5.2.0
tomcat - addressed in versions 9.0.21-1.fc29, 9.0.21-1.fc30

External References

Related Security Bulletins