Resource management error in Apache Tomcat - CVE-2019-10072
Published: September 10, 2019 / Updated: January 20, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incomplete fix for SB2019020812 when processing HTTP/2 requests. A remote attacker can perform denial of service attack by not sending WINDOW_UPDATE messages for the connection window (stream 0).
Affected software
JBoss Enterprise Web Server
Dell Support Assist Enterprise
IBM Engineering Requirements Management DOORS Next
Oracle Retail Xstore Point of Service
Power Protect Data Manager (PPDM)
MySQL Enterprise Monitor
Oracle Database Server
Oracle Communications Session Route Manager
Oracle Communications Element Manager
Oracle Communications Session Report Manager
tomcat8 (Ubuntu package)
tomcat9 (Debian package)
Oracle Agile PLM Framework
Oracle Communications Instant Messaging Server
Opensuse
Siebel Apps - Marketing
How to mitigate CVE-2019-10072
Dell Support Assist Enterprise - update to 4.00.06.00
JBoss Enterprise Web Server - update to 5.2.0
MySQL Enterprise Monitor - update to 8.0.18
tomcat8 (Ubuntu package) - addressed in versions 8.0.32-1ubuntu1.10, 8.5.39-1ubuntu1~18.04.3
tomcat9 (Debian package) - update to 9.0.31-1~deb10u1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Power Protect Data Manager (PPDM) - update to 19.2
External References
Related Security Bulletins
- Ubuntu update for Tomcat
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Multple vulnerabilities in Red Hat JBoss Web Server
- Multiple vulnerabilities in Oracle Database Server
- Multiple vulnerabilities in Oracle Communications Instant Messaging Server
- OpenSUSE Linux update for tomcat
- Multiple vulnerabilities in Oracle Communications Element Manager
- Multiple vulnerabilities in Oracle Communications Session Report Manager
- Multiple vulnerabilities in Oracle Communications Session Route Manager
- Multiple vulnerabilities in Oracle Retail Xstore Point of Service
- Debian update for tomcat9
- Multiple vulnerabilities in Oracle Agile PLM Framework
- Resource management error in MySQL Enterprise Monitor
- Multiple vulnerabilities in Siebel Apps - Marketing
- Resource management error in Dell EMC Power Protect Data Manager
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Multiple vulnerabilities in Dell Support Assist Enterprise