Junglewise Threat Intelligence

CVE-2019-0199: Apache Tomcat Denial of Service in HTTP/2 implementation

CVE-2019-0199 · Severity: high · CVSS 7.5 · Published 2020-06-15

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat is a widely used web server for hosting Java-based applications. A flaw in its handling of modern web traffic (HTTP/2) allows an attacker to overwhelm the server by keeping connections open without sending data. This can lead to a complete service outage, preventing legitimate users from accessing hosted applications.

Technical details

The HTTP/2 implementation in Apache Tomcat fails to properly limit the number of SETTINGS frames and allows clients to maintain open streams without active data transfer. By exploiting the Servlet API's blocking I/O, a remote attacker can keep these streams open indefinitely, eventually exhausting the server's thread pool. This results in a Denial of Service (DoS) condition where the server can no longer process new requests. The vulnerability is patched in versions 9.0.16 and 8.5.38.

Affected products

  • Apache Tomcat 9.0.0.M1 to 9.0.14, 8.5.0 to 8.5.37

Timeline

  • 2019-04-10: advisory: NVD publication date
  • 2020-06-15: disclosed: GitHub Advisory published

References

Related threats