Resource management error in Apache Tomcat - CVE-2020-13934

 

Resource management error in Apache Tomcat - CVE-2020-13934

Published: July 14, 2020 / Updated: July 15, 2020


Vulnerability identifier: #VU29724
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13934
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources when processing h2 direct connections. A remote attacker can pass specially crafted HTTP/2 requests to the server and consume all available memory.


Affected software

Apache Tomcat
Amazon Linux AMI
Debian Linux
Opensuse
Ubuntu
Dell Support Assist Enterprise
IBM Engineering Requirements Management DOORS Next
libtomcat9-embed-java (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
tomcat9-common (Ubuntu package)
tomcat9 (Debian package)

How to mitigate CVE-2020-13934

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.57, 9.0.37, 10.0.0-M7
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
libtomcat9-embed-java (Ubuntu package) - update to 9.0.31-1ubuntu0.1
libtomcat9-java (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9 (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9-common (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u2

External References

Related Security Bulletins