HIGH · 7.5

CVE-2020-17527

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream rec...

Vulnerability Description

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ApacheTomcat>= 8.5.1, <= 8.5.59
NetappElement Plug-In-
NetappOncommand System Manager>= 3.0.0, <= 3.1.3
DebianDebian Linux9.0
OracleBlockchain Platform< 21.1.2
OracleCommunications Cloud Native Core Binding Support Function1.10.0
OracleCommunications Cloud Native Core Policy1.14.0
OracleCommunications Instant Messaging Server10.0.1.5.0
OracleInstantis Enterprisetrack17.1
OracleMysql Enterprise Monitor< 8.0.23
OracleSd-Wan Edge9.0
OracleWorkload Manager18c

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-17527?

CVE-2020-17527 is a vulnerability with a CVSS score of 7.5 (HIGH). While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream rec...

How severe is CVE-2020-17527?

CVE-2020-17527 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-17527?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Netapp Element Plug-In, Netapp Oncommand System Manager, Debian Debian Linux, Oracle Blockchain Platform.