DNA View

CVE-2019-0199

Low
Low Medium High Critical
CVSS Score
Published: Apr 10, 2019
Last Modified: Nov 21, 2024

Vulnerability Description

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for requests that utilised the Servlet API's blocking I/O, clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

Known Affected Software

1 configuration(s) from 1 vendor(s)

tomcat
Version:
9.0.0
CPE:
cpe:2.3:a:apache:tomcat:9.0.0:-:*:*:*:*:*:*
This vulnerability affects 1 software configuration(s). Ensure you patch all affected systems.

References & Resources

Severity Details

out of 10.0
Low

Weakness Type (CWE)

CWE-400

Uncontrolled Resource Consumption

Description
The product does not properly control the allocation and maintenance of a limited resource.
Exploit Likelihood
High
Typical Severity
High
Abstraction Level
Class

Key Information

Published Date
April 10, 2019