Resource management error in Apache Tomcat - CVE-2020-17527

 

Resource management error in Apache Tomcat - CVE-2020-17527

Published: December 3, 2020 / Updated: December 4, 2020


Vulnerability identifier: #VU48779
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-17527
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to improper management of internal resources within the application when processing HTTP/2 requests in Apache Tomcat. The web server can re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. As a result a remote attacker can obtain sensitive information from another HTTP request.


Affected software

Apache Tomcat
Arch Linux
Amazon Linux AMI
Gentoo Linux
Oracle Solaris
Ubuntu
openEuler
Oracle Communications Cloud Native Core Binding Support Function
Oracle SD-WAN Edge
Oracle Blockchain Platform
Oracle Communications Cloud Native Core Policy
Traffix SDC
IBM Qradar SIEM
MySQL Enterprise Monitor
Oracle Database Server
Big Data Spatial and Graph
tomcat9 (Debian package)
undertow-javadoc
undertow
libtomcat9-embed-java (Ubuntu package)
tomcat9-common (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
IBM Engineering Requirements Management DOORS Next
Oracle Retail Xstore Point of Service
Oracle Communications Pricing Design Center
Instantis EnterpriseTrack
Fuse

How to mitigate CVE-2020-17527

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.60, 9.0.40, 10.0.0-M10
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 8, 7.4.3 Fix Pack 1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
undertow-javadoc - update to 1.4.0-8
undertow - update to 1.4.0-8
Big Data Spatial and Graph - update to 3.1
Fuse - update to 7.10.0
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9 (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
Oracle Blockchain Platform - update to 21.1.2

External References

Related Security Bulletins