Resource management error in Apache Tomcat - CVE-2019-10072

 

Resource management error in Apache Tomcat - CVE-2019-10072

Published: September 10, 2019 / Updated: January 20, 2020


Vulnerability identifier: #VU20992
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10072
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incomplete fix for SB2019020812 when processing HTTP/2 requests. A remote attacker can perform denial of service attack by not sending WINDOW_UPDATE messages for the connection window (stream 0).


Affected software

Apache Tomcat
JBoss Enterprise Web Server
Dell Support Assist Enterprise
IBM Engineering Requirements Management DOORS Next
Oracle Retail Xstore Point of Service
Power Protect Data Manager (PPDM)
MySQL Enterprise Monitor
Oracle Database Server
Oracle Communications Session Route Manager
Oracle Communications Element Manager
Oracle Communications Session Report Manager
tomcat8 (Ubuntu package)
tomcat9 (Debian package)
Oracle Agile PLM Framework
Oracle Communications Instant Messaging Server
Opensuse
Siebel Apps - Marketing

How to mitigate CVE-2019-10072

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.40, 9.0.20
Dell Support Assist Enterprise - update to 4.00.06.00
JBoss Enterprise Web Server - update to 5.2.0
MySQL Enterprise Monitor - update to 8.0.18
tomcat8 (Ubuntu package) - addressed in versions 8.0.32-1ubuntu1.10, 8.5.39-1ubuntu1~18.04.3
tomcat9 (Debian package) - update to 9.0.31-1~deb10u1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Power Protect Data Manager (PPDM) - update to 19.2

External References

Related Security Bulletins