HIGH · 7.5

CVE-2020-13935

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could tr...

Vulnerability Description

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ApacheTomcat>= 7.0.27, <= 7.0.104
DebianDebian Linux9.0
NetappOncommand System Manager>= 3.0.0, <= 3.1.3
OpensuseLeap15.1
CanonicalUbuntu Linux16.04
McafeeEpolicy Orchestrator5.9.0
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Plm9.3.3
OracleBlockchain Platform< 21.1.2
OracleCommerce Guided Search11.3.2
OracleCommunications Cloud Native Core Policy1.14.0
OracleCommunications Instant Messaging Server10.0.1.5.0
OracleFmw Platform12.2.1.3.0
OracleInstantis Enterprisetrack17.1
OracleManaged File Transfer12.2.1.3.0
OracleMysql Enterprise Monitor<= 8.0.21
OracleSiebel Ui Framework<= 20.12
OracleWorkload Manager12.2.0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-13935?

CVE-2020-13935 is a vulnerability with a CVSS score of 7.5 (HIGH). The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could tr...

How severe is CVE-2020-13935?

CVE-2020-13935 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-13935?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Debian Debian Linux, Netapp Oncommand System Manager, Opensuse Leap, Canonical Ubuntu Linux.