HIGH · 7.5

CVE-2020-9490

Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resour...

Vulnerability Description

Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ApacheHttp Server>= 2.4.20, < 2.4.46
OracleCommunications Element Manager>= 8.2.0, <= 8.2.2
OracleCommunications Session Report Manager>= 8.2.0, <= 8.2.2
OracleCommunications Session Route Manager>= 8.2.0, <= 8.2.2
OracleEnterprise Manager Ops Center12.4.0.0
OracleHyperion Infrastructure Technology11.1.2.4
OracleInstantis Enterprisetrack17.1
OracleZfs Storage Appliance Kit8.8
OpensuseLeap15.1
DebianDebian Linux10.0
FedoraprojectFedora31
CanonicalUbuntu Linux16.04
RedhatSoftware Collections1.0
RedhatEnterprise Linux6.0
RedhatOpenstack16.1
RedhatOpenstack For Ibm Power16.1
RedhatEnterprise Linux Eus8.1
RedhatEnterprise Linux For Ibm Z Systems8.0
RedhatEnterprise Linux For Ibm Z Systems Eus8.1
RedhatEnterprise Linux For Power Little Endian8.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-9490?

CVE-2020-9490 is a vulnerability with a CVSS score of 7.5 (HIGH). Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resour...

How severe is CVE-2020-9490?

CVE-2020-9490 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-9490?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Oracle Communications Element Manager, Oracle Communications Session Report Manager, Oracle Communications Session Route Manager, Oracle Enterprise Manager Ops Center.