HIGH · 7.5

CVE-2020-13934

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of s...

Vulnerability Description

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ApacheTomcat>= 8.5.1, <= 8.5.56
DebianDebian Linux9.0
NetappOncommand System Manager>= 3.0.0, <= 3.1.3
OpensuseLeap15.1
CanonicalUbuntu Linux20.04
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Plm9.3.3
OracleCommunications Instant Messaging Server10.0.1.5.0
OracleFmw Platform12.2.1.3.0
OracleInstantis Enterprisetrack17.1
OracleManaged File Transfer12.2.1.3.0
OracleMysql Enterprise Monitor<= 8.0.21
OracleSiebel Ui Framework<= 20.12
OracleWorkload Manager12.2.0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-13934?

CVE-2020-13934 is a vulnerability with a CVSS score of 7.5 (HIGH). An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of s...

How severe is CVE-2020-13934?

CVE-2020-13934 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-13934?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Debian Debian Linux, Netapp Oncommand System Manager, Opensuse Leap, Canonical Ubuntu Linux.