CVE-2019-10072
published 2019-06-21CVE-2019-10072: The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and…
PriorityP357high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
72.99%
99.4th percentile
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | 8.5.0 – 8.5.40 | — |
| apache | tomcat | 9.0.1 – 9.0.19 | — |
| debian | tomcat9 | < tomcat9 9.0.22-1 (bookworm) | tomcat9 9.0.22-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Check Point IPS signature available for this CVE — detect Apache Tomcat HTTP/2 connection window exhaustion DoS attempts ↗
- ·Affected Apache Tomcat versions: 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 — exploit targets HTTP/2 by withholding WINDOW_UPDATE messages for the connection window (stream 0), causing server-side thread exhaustion ↗
- ·Mitigation: disabling HTTP/2 in Tomcat configuration prevents exploitation — pki-servlet-container is not vulnerable in its default configuration because HTTP/2 is not enabled by default ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tomcat9 vulnerabilities
osv·2019-09-18·CVSS 7.5
CVE-2019-0221 [HIGH] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that the Tomcat 9 SSI printenv command echoed user
provided data without escaping it. An attacker could possibly use this
issue to perform an XSS attack. (CVE-2019-0221)
It was discovered that Tomcat 9 did not address HTTP/2 connection window
exhaustion on write while addressing CVE-2019-0199. An attacker could
possibly use this issue to cause a denial of service. (CVE-2019-10072)
OSV
tomcat8 vulnerabilities
osv·2019-09-10·CVSS 7.5
CVE-2019-0221 [HIGH] tomcat8 vulnerabilities
tomcat8 vulnerabilities
It was discovered that the Tomcat 8 SSI printenv command echoed user
provided data without escaping it. An attacker could possibly use this
issue to perform an XSS attack. (CVE-2019-0221)
It was discovered that Tomcat 8 did not address HTTP/2 connection window
exhaustion on write while addressing CVE-2019-0199. An attacker could
possibly use this issue to cause a denial of service. (CVE-2019-10072)
OSV
Improper Locking in Apache Tomcat
osv·2019-06-26·CVSS 7.5
CVE-2019-10072 [HIGH] Improper Locking in Apache Tomcat
Improper Locking in Apache Tomcat
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
GHSA
Improper Locking in Apache Tomcat
ghsa·2019-06-26·CVSS 7.5
CVE-2019-10072 [HIGH] CWE-667 Improper Locking in Apache Tomcat
Improper Locking in Apache Tomcat
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
OSV
CVE-2019-10072: The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9
osv·2019-06-21·CVSS 7.5
CVE-2019-10072 [HIGH] CVE-2019-10072: The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Mktg/Campaign Mgmt (Apache Tomcat) — CVE-2019-10072
vendor_oracle·2020-10-15·CVSS 7.5
CVE-2019-10072 [HIGH] Oracle Oracle Siebel CRM Risk Matrix: Mktg/Campaign Mgmt (Apache Tomcat) — CVE-2019-10072
Oracle Oracle Siebel CRM Risk Matrix: Mktg/Campaign Mgmt (Apache Tomcat) vulnerability
CVE: CVE-2019-10072
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Tomcat) — CVE-2019-10072
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2019-10072 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Core (Apache Tomcat) — CVE-2019-10072
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Tomcat) vulnerability
CVE: CVE-2019-10072
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Database Server Risk Matrix: Workload Manager (Apache Tomcat) — CVE-2019-10072
vendor_oracle·2020-01-15·CVSS 7.5
CVE-2019-10072 [HIGH] Oracle Oracle Database Server Risk Matrix: Workload Manager (Apache Tomcat) — CVE-2019-10072
Oracle Oracle Database Server Risk Matrix: Workload Manager (Apache Tomcat) vulnerability
CVE: CVE-2019-10072
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2019-09-18·CVSS 7.5
CVE-2019-0221 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat 9.
It was discovered that the Tomcat 9 SSI printenv command echoed user
provided data without escaping it. An attacker could possibly use this
issue to perform an XSS attack. (CVE-2019-0221)
It was discovered that Tomcat 9 did not address HTTP/2 connection window
exhaustion on write while addressing CVE-2019-0199. An attacker could
possibly use this issue to cause a denial of service. (CVE-2019-10072)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2019-09-10·CVSS 7.5
CVE-2019-0221 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat 8.
It was discovered that the Tomcat 8 SSI printenv command echoed user
provided data without escaping it. An attacker could possibly use this
issue to perform an XSS attack. (CVE-2019-0221)
It was discovered that Tomcat 8 did not address HTTP/2 connection window
exhaustion on write while addressing CVE-2019-0199. An attacker could
possibly use this issue to cause a denial of service. (CVE-2019-10072)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199
vendor_redhat·2019-06-21·CVSS 7.5
CVE-2019-10072 [HIGH] CWE-400 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199
tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
Mitigation: pki-servlet-container does not use HTTP/2 in its default configuration.
Package: tomcat (Red Hat BPM Suite 6) - Out of support scope
Package: tomcat (Red Hat Enterprise Linux 6) - Not affected
Package: tomcat (Red Hat Enterprise Linux 7) - Not affected
Package: pki-deps:10.6/pki-servlet-container (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2019-10072: tomcat9 - The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection w...
vendor_debian·2019·CVSS 7.5
CVE-2019-10072 [HIGH] CVE-2019-10072: tomcat9 - The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection w...
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
Scope: local
bookworm: resolved (fixed in 9.0.22-1)
bullseye: resolved (fixed in 9.0.22-1)
forky: resolved (fixed in 9.0.22-1)
sid: resolved (fixed in 9.0.22-1)
trixie: resolved (fixed in 9.0.22-1)
No detection rules found.
No public exploits indexed.
HackerOne
Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
hackerone·2020-06-11·CVSS 4.3
[MEDIUM] Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
**Summary:**
There are multiple issues found on ███:
1. ███████/examples/ - Apache Tomcat examples are available for public. Multiple issues - session and cookies manipulation, internals IP disclosure.
2. Error page contains information about Apache Tomcat version
3. Reported Tomcat version is vulnerable. Multiple CVEs - critical, high and medium
**Description:**
1. Examples are available by link: ███████/examples/
2. Information disclosure about Apache Tomcat version
3. Vulnerable version Apache Tomcat/8.5.33
https://nvd.nist.gov/vuln/detail/CVE-2020-1938
Base Score: 9.8 CRITICALVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
https://nvd.nist.gov/vuln/detail/CVE-2019-0232
Base Score
Bugzilla
CVE-2019-10072 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199
bugzilla·2019-06-25·CVSS 7.5
CVE-2019-10072 [HIGH] CVE-2019-10072 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199
CVE-2019-10072 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write. By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
References:
http://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.20
http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.41
http://mail-archives.us.apache.org/mod_mbox/www-announce/201906.mbox/%3Cca69531a-1592-be7b-60ce-729549c7f812%40apache.org%3E
Upstream commits:
Tomcat 9.0:
https://github.com/apache/tomcat/commit/7f748eb
https://github.com/apache/tomcat/commit/ada725a
Bugzilla
CVE-2019-10072 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199 [epel-all]
bugzilla·2019-06-25·CVSS 7.5
CVE-2019-10072 [HIGH] CVE-2019-10072 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199 [epel-all]
CVE-2019-10072 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2019-10072 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199 [fedora-all]
bugzilla·2019-06-25·CVSS 7.5
CVE-2019-10072 [HIGH] CVE-2019-10072 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199 [fedora-all]
CVE-2019-10072 tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Checkpoint
29th June – Threat Intelligence Bulletin
blogs_checkpoint·2020-06-29
CVE-2019-10072 29th June – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th June – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 29th June 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point researchers have discovered an ongoing, evolving campaign from a known hacking group called “DarkCrewFriends.” This campaign targets PHP servers, focusing on creating a botnet infrastructure that can be leveraged for several purposes such as monetization and shutting down critical services.
Check Point IPS p
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.htmlhttp://www.securityfocus.com/bid/108874https://access.redhat.com/errata/RHSA-2019:3929https://access.redhat.com/errata/RHSA-2019:3931https://lists.apache.org/thread.html/df1a2c1b87c8a6c500ecdbbaf134c7f1491c8d79d98b48c6b9f0fa6a%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190625-0002/https://support.f5.com/csp/article/K17321505https://usn.ubuntu.com/4128-1/https://usn.ubuntu.com/4128-2/https://www.debian.org/security/2020/dsa-4680https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_29http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.htmlhttp://www.securityfocus.com/bid/108874https://access.redhat.com/errata/RHSA-2019:3929https://access.redhat.com/errata/RHSA-2019:3931https://lists.apache.org/thread.html/df1a2c1b87c8a6c500ecdbbaf134c7f1491c8d79d98b48c6b9f0fa6a%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190625-0002/https://support.f5.com/csp/article/K17321505https://usn.ubuntu.com/4128-1/https://usn.ubuntu.com/4128-2/https://www.debian.org/security/2020/dsa-4680https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.synology.com/security/advisory/Synology_SA_19_29
2019-06-21
Published