← All CVEs

CVE-2020-13934

high · 7.5

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.

7.5
CVSS
64.1%
EPSS (exploit prob.)
99th
EPSS percentile
2020-07-14
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-401CWE-476

Affected products

VendorProductAffected versions
apachetomcat>= 8.5.1, <= 8.5.56
apachetomcat>= 9.0.1, <= 9.0.36
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat10.0.0
apachetomcat10.0.0
apachetomcat10.0.0
apachetomcat10.0.0
apachetomcat10.0.0
apachetomcat10.0.0
debiandebian_linux9.0
debiandebian_linux10.0
netapponcommand_system_manager>= 3.0.0, <= 3.1.3
opensuseleap15.1
opensuseleap15.2
canonicalubuntu_linux20.04
oracleagile_engineering_data_management6.2.1.0
oracleagile_product_lifecycle_management9.3.3
oracleagile_product_lifecycle_management9.3.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-13934