Lucene search

K
ibmIBM6631708C569950EFA232585E26AAA734D58898A14D40C73A6F9CDC8C2340AC59
HistoryJul 24, 2020 - 9:16 p.m.

Security Bulletin: CVE-2019-0199 The HTTP/2 implementation in embded Apache Tomcat Denial of Service Vulnerability

2020-07-2421:16:35
www.ibm.com
18

0.727 High

EPSS

Percentile

98.1%

Summary

Urbancode Deploy (UCD): The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for requests that utilised the Servlet API’s blocking I/O, clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

Vulnerability Details

CVEID:CVE-2019-0199
**DESCRIPTION:**Apache Tomcat is vulnerable to a denial of service, caused by the acceptance of streams with excessive numbers of SETTINGS frames and the permitting of clients to keep streams open without reading/writing request data by the HTTP/2 implementation. By sending excessive SETTINGS frames, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/158637 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
UCD - IBM UrbanCode Deploy All

Remediation/Fixes

Upgrade to IBM UrbanCode Deploy 7.0.3.3 and 6.2.7.5 or later.

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm urbancode deployeq7.0.3.