CVE-2019-0199Uncontrolled Resource Consumption in Apache Tomcat

Severity
7.5HIGHNVD
EPSS
65.6%
top 1.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateJun 15

Description

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for requests that utilised the Servlet API's blocking I/O, clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDapache/tomcat8.5.08.5.37+2
CVEListV5apache_software_foundation/apache_tomcatApache Tomcat 9.0.0.M1 to 9.0.14, 8.5.0 to 8.5.37

🔴Vulnerability Details

7
GHSA
Apache Tomcat Denial of Service vulnerability2020-06-15
OSV
Apache Tomcat Denial of Service vulnerability2020-06-15
OSV
tomcat9 vulnerabilities2019-09-18
OSV
tomcat8 vulnerabilities2019-09-10
GHSA
Improper Locking in Apache Tomcat2019-06-26

📋Vendor Advisories

4
Red Hat
tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-01992019-06-21
Red Hat
tomcat: Apache Tomcat HTTP/2 DoS2019-03-25
Debian
CVE-2019-0199: tomcat9 - The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.3...2019
Apache
Apache tomcat: CVE-2019-0199

💬Community

7
Bugzilla
Mojarra: Path traversal in ResourceManager.java:getResourceLibraryContracts() via the con parameter2020-02-20
Bugzilla
CVE-2020-6950 Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-143712020-02-20
Bugzilla
CVE-2019-10072 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-01992019-06-25
Bugzilla
CVE-2019-10072 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199 [epel-all]2019-06-25
Bugzilla
CVE-2019-10072 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199 [fedora-all]2019-06-25
CVE-2019-0199 — Uncontrolled Resource Consumption | cvebase