Lucene search

K
ibmIBMF4A4DE4779BD0C5EB9721FAA09D23035B36D4C6ECC92A86784334BD52BD8BEB3
HistoryAug 15, 2019 - 5:31 p.m.

Security Bulletin: Apache Tomcat as used in IBM QRadar SIEM is vulnerable to a denial of service (CVE-2019-10072)

2019-08-1517:31:45
www.ibm.com
21

0.17 Low

EPSS

Percentile

96.1%

Summary

Open source Apache Tomcat vulnerable to a publicly disclosed vulnerability

Vulnerability Details

CVEID: CVE-2019-10072
**Description:**Apache Tomcat is vulnerable to a denial of service, caused by HTTP/2 connection window exhaustion on write. By failing to send WINDOW_UPDATE messages, a remote attacker could exploit this vulnerability to block threads on the server and causing a denial of service.
**CVSS Base Score:**7.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/162806&gt; for the current score
**CVSS Environmental Score:***Undefined
**CVSS Vector:**CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products and Versions

ยท IBM QRadar 7.3 to 7.3.2 Patch 3

Remediation/Fixes

IBM QRadar/QRM/QVM/QRIF/QNI 7.3.2 Patch 4

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm security qradar siemeq7.3