MEDIUM · 4.2

CVE-2019-0197

A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 ...

Vulnerability Description

A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https: and did not set "H2Upgrade on" are unaffected by this issue.

CVSS Score

4.2

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
ApacheHttp Server>= 2.4.34, <= 2.4.38
CanonicalUbuntu Linux16.04
FedoraprojectFedora30
OpensuseLeap15.0
RedhatJboss Core Services1.0
RedhatEnterprise Linux6.0
OracleCommunications Session Report Manager8.0.0
OracleCommunications Session Route Manager8.0.0
OracleEnterprise Manager Ops Center12.3.3
OracleHttp Server12.2.1.3.0
OracleInstantis Enterprisetrack17.1
OracleRetail Xstore Point Of Service7.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-0197?

CVE-2019-0197 is a vulnerability with a CVSS score of 4.2 (MEDIUM). A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 ...

How severe is CVE-2019-0197?

CVE-2019-0197 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-0197?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Canonical Ubuntu Linux, Fedoraproject Fedora, Opensuse Leap, Redhat Jboss Core Services.