Resource management error in Apache Tomcat - CVE-2020-11996
Published: June 27, 2020 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources with the application when processing HTTP/2 requests. A remote attacker can send specially crafted sequence of HTTP/2 requests to the affected server and trigger high CPU load for several seconds. A large number of such requests causes denial of service.
Affected software
JBoss Enterprise Web Server
Arch Linux
Debian Linux
Opensuse
Ubuntu
Dell Support Assist Enterprise
IBM Engineering Requirements Management DOORS Next
libtomcat9-embed-java (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
tomcat9-common (Ubuntu package)
tomcat9 (Debian package)
How to mitigate CVE-2020-11996
Dell Support Assist Enterprise - update to 4.00.06.00
JBoss Enterprise Web Server - update to 5.4.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
libtomcat9-embed-java (Ubuntu package) - update to 9.0.31-1ubuntu0.1
libtomcat9-java (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9 (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9-common (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u2
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Denial of service in Apache Tomcat
- Arch Linux update for tomcat8
- OpenSUSE Linux update for tomcat
- OpenSUSE Linux update for tomcat
- Red Hat JBoss Web Server update for Apache Tomcat
- Debian update for tomcat9
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Ubuntu update for tomcat9