Resource management error in Apache Tomcat - CVE-2020-13934
Published: July 14, 2020 / Updated: July 15, 2020
Vulnerability identifier: #VU29724
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13934
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources when processing h2 direct connections. A remote attacker can pass specially crafted HTTP/2 requests to the server and consume all available memory.
Affected software
Apache Tomcat
Amazon Linux AMI
Debian Linux
Opensuse
Ubuntu
Dell Support Assist Enterprise
IBM Engineering Requirements Management DOORS Next
libtomcat9-embed-java (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
tomcat9-common (Ubuntu package)
tomcat9 (Debian package)
Amazon Linux AMI
Debian Linux
Opensuse
Ubuntu
Dell Support Assist Enterprise
IBM Engineering Requirements Management DOORS Next
libtomcat9-embed-java (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
tomcat9-common (Ubuntu package)
tomcat9 (Debian package)
How to mitigate CVE-2020-13934
Install updates from vendor's website.
Apache Tomcat - addressed in versions 8.5.57, 9.0.37, 10.0.0-M7
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
libtomcat9-embed-java (Ubuntu package) - update to 9.0.31-1ubuntu0.1
libtomcat9-java (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9 (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9-common (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u2
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
libtomcat9-embed-java (Ubuntu package) - update to 9.0.31-1ubuntu0.1
libtomcat9-java (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9 (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9-common (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u2
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Tomcat
- OpenSUSE Linux update for tomcat
- OpenSUSE Linux update for tomcat
- Amazon Linux AMI update for tomcat8
- Debian update for tomcat9
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Ubuntu update for tomcat9