CVE-2019-10072

HIGH

Apache Tomcat <9.0.19, <8.5.40 - DoS

Title source: llm
STIX 2.1

Description

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

References (20)

Core 20
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108874
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4128-1/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4128-2/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3929
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3931
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2020/dsa-4680
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190625-0002/
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K17321505

Scores

CVSS v3 7.5
EPSS 0.7130
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-667
Status published
Products (3)
apache/tomcat 9.0.0 milestone1 (27 CPE variants)
apache/tomcat 8.5.0 - 8.5.40
org.apache.tomcat.embed/tomcat-embed-core 9.0.0.M1 - 9.0.20Maven
Published Jun 21, 2019
Tracked Since Feb 18, 2026