Vulnerability Description
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | >= 8.5.0, <= 8.5.55 |
| Canonical | Ubuntu Linux | 20.04 |
| Oracle | Mysql Enterprise Monitor | <= 8.0.21 |
| Oracle | Siebel Ui Framework | <= 20.12 |
| Oracle | Workload Manager | 12.2.0.1 |
| Opensuse | Leap | 15.1 |
| Debian | Debian Linux | 9.0 |
| Netapp | Oncommand System Manager | 3.0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00064.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00072.htmlMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r2529016c311ce9485e6f173446d469600fdfbb94dc
- https://lists.apache.org/thread.html/r3ea96d8f36dd404acce83df8aeb22a9e807d6c13ca
- https://lists.apache.org/thread.html/r5541ef6b6b68b49f76fc4c45695940116da2bcbe03Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/r5a4f80a6acc6607d61dae424b643b594c6188dd4e1
- https://lists.apache.org/thread.html/r6c29801370a36c1a5159679269777ad0c73276d301
- https://lists.apache.org/thread.html/r74f5a8204efe574cbfcd95b2a16236fe95beb45c4d
- https://lists.apache.org/thread.html/r8f3d416c193bc9384a8a7dd368623d441f5fcaff10
- https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c
- https://lists.apache.org/thread.html/r93ca628ef3a4530dfe5ac49fddc795f0920a4b2a40
- https://lists.apache.org/thread.html/r9ad911fe49450ed9405827af0e7a74104041081ff9
- https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15e
- https://lists.apache.org/thread.html/rb4ee49ecc4c59620ffd5e66e84a17e526c2c3cfa95
- https://lists.apache.org/thread.html/rb820f1a2a02bf07414be12c653c2ab5321fd87b9bf
FAQ
What is CVE-2020-11996?
CVE-2020-11996 is a vulnerability with a CVSS score of 7.5 (HIGH). A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient n...
How severe is CVE-2020-11996?
CVE-2020-11996 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11996?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Canonical Ubuntu Linux, Oracle Mysql Enterprise Monitor, Oracle Siebel Ui Framework, Oracle Workload Manager.