Resource management error in Apache Tomcat - CVE-2020-11996

 

Resource management error in Apache Tomcat - CVE-2020-11996

Published: June 27, 2020 / Updated: July 28, 2020


Vulnerability identifier: #VU29333
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11996
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources with the application when processing HTTP/2 requests. A remote attacker can send specially crafted sequence of HTTP/2 requests to the affected server and trigger high CPU load for several seconds. A large number of such requests causes denial of service.


Affected software

Apache Tomcat
JBoss Enterprise Web Server
Arch Linux
Debian Linux
Opensuse
Ubuntu
Dell Support Assist Enterprise
IBM Engineering Requirements Management DOORS Next
libtomcat9-embed-java (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
tomcat9-common (Ubuntu package)
tomcat9 (Debian package)

How to mitigate CVE-2020-11996

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.56, 9.0.36, 10.0.0-M6
Dell Support Assist Enterprise - update to 4.00.06.00
JBoss Enterprise Web Server - update to 5.4.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
libtomcat9-embed-java (Ubuntu package) - update to 9.0.31-1ubuntu0.1
libtomcat9-java (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9 (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9-common (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins