Resource management error in Apache Tomcat - CVE-2020-17527
Published: December 3, 2020 / Updated: December 4, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper management of internal resources within the application when processing HTTP/2 requests in Apache Tomcat. The web server can re-use an HTTP request header value from the previous stream received on an
HTTP/2 connection for the request associated with the subsequent stream. As a result a remote attacker can obtain sensitive information from another HTTP request.
Affected software
Arch Linux
Amazon Linux AMI
Gentoo Linux
Oracle Solaris
Ubuntu
openEuler
Oracle Communications Cloud Native Core Binding Support Function
Oracle SD-WAN Edge
Oracle Blockchain Platform
Oracle Communications Cloud Native Core Policy
Traffix SDC
IBM Qradar SIEM
MySQL Enterprise Monitor
Oracle Database Server
Big Data Spatial and Graph
tomcat9 (Debian package)
undertow-javadoc
undertow
libtomcat9-embed-java (Ubuntu package)
tomcat9-common (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
IBM Engineering Requirements Management DOORS Next
Oracle Retail Xstore Point of Service
Oracle Communications Pricing Design Center
Instantis EnterpriseTrack
Fuse
How to mitigate CVE-2020-17527
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 8, 7.4.3 Fix Pack 1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
undertow-javadoc - update to 1.4.0-8
undertow - update to 1.4.0-8
Big Data Spatial and Graph - update to 3.1
Fuse - update to 7.10.0
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9 (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
Oracle Blockchain Platform - update to 21.1.2
External References
- https://lists.apache.org/thread.html/r8a227ac6a755a6406c1cc47dd48800e973d4cf13fe7fe68ac59c679c@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/raa0e9ad388c1e6fd1e301b5e080f9439f64cb4178119a86a4801cc53@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5%40%3Cannounce.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/rce5ac9a40173651d540babce59f6f3825f12c6d4e886ba00823b11e5@%3Cannounce.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rd5babd13d7a350b369b2f647b4dd32ce678af42f9aba5389df1ae6ca@%3Cusers.tomcat.apache.org%3E
Related Security Bulletins
- Information disclosure in Apache Tomcat
- Arch Linux update for tomcat8
- Arch Linux update for tomcat9
- Amazon Linux AMI update for tomcat8
- Gentoo update for Apache Tomcat
- Information disclosure in Apache Tomcat component in F5 Traffix SDC
- Amazon Linux AMI update for tomcat8
- Multiple vulnerabilities in Oracle Solaris
- Debian update for tomcat9
- Multiple vulnerabilities in Oracle Database Server
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in Oracle SD-WAN Edge
- Multiple vulnerabilities in Instantis EnterpriseTrack
- Multiple vulnerabilities in Big Data Spatial and Graph
- Multiple vulnerabilities in Oracle Communications Pricing Design Center
- Multiple vulnerabilities in Oracle Retail Xstore Point of Service
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Ubuntu update for tomcat9
- Multiple vulnerabilities in Oracle Blockchain Platform
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Multiple vulnerabilities in Fuse 7.10
- openEuler update for undertow