ZeroHour

CVE-2020-13934

CVSS 3.1
7.5 high
EPSS
64%p99
Published
()
Modified
Description

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.

Vendors
apachedebiannetappopensusecanonicaloracle
Products
tomcat, debian linux, oncommand system manager, leap, ubuntu linux, agile engineering data management, agile product lifecycle management, communications instant messaging server, fmw platform, instantis enterprisetrack, managed file transfer, mysql enterprise monitor
Weakness
CWE-401, CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.