CVE-2020-11996: High severity IBM Data Risk Manager vulnerability
A specially crafted sequence of HTTP/2 requests could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
Reference: https://tomcat.apache.org/security-8.html
Other sources
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
Apache Tomcat is vulnerable to a denial of service. By sending a specially crafted sequence of HTTP/2 requests, a remote attacker could exploit this vulnerability to trigger high CPU usage for several seconds.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jws5-jboss-loggingto a version that resolves this vulnerability.Fixed in 0:3.4.1-1.Final_redhat_00001.1.el6 - Upgrade
Upgrade
redhat/jws5-tomcatto a version that resolves this vulnerability.Fixed in 0:9.0.36-6.redhat_5.2.el6 - Upgrade
Upgrade
redhat/jws5-tomcat-nativeto a version that resolves this vulnerability.Fixed in 0:1.2.25-2.redhat_2.el6 - Upgrade
Upgrade
redhat/jws5-jboss-loggingto a version that resolves this vulnerability.Fixed in 0:3.4.1-1.Final_redhat_00001.1.el7 - Upgrade
Upgrade
redhat/jws5-tomcatto a version that resolves this vulnerability.Fixed in 0:9.0.36-6.redhat_5.2.el7 - Upgrade
Upgrade
redhat/jws5-tomcat-nativeto a version that resolves this vulnerability.Fixed in 0:1.2.25-2.redhat_2.el7 - Upgrade
Upgrade
redhat/jws5-jboss-loggingto a version that resolves this vulnerability.Fixed in 0:3.4.1-1.Final_redhat_00001.1.el8 - Upgrade
Upgrade
redhat/jws5-tomcatto a version that resolves this vulnerability.Fixed in 0:9.0.36-6.redhat_5.2.el8 - Upgrade
Upgrade
redhat/jws5-tomcat-nativeto a version that resolves this vulnerability.Fixed in 0:1.2.25-2.redhat_2.el8 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 8.5.55 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 9.0.35 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 10.0.0-M5 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 10.0.0 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 9.0.36 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.5.56 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.70-2Fixed in 9.0.95-1Fixed in 9.0.118-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-11996?
CVE-2020-11996 is a vulnerability in Apache Tomcat that could trigger high CPU usage and make the server unresponsive.
How does CVE-2020-11996 impact Apache Tomcat?
CVE-2020-11996 can cause high CPU usage in Apache Tomcat and make the server unresponsive.
Which versions of Apache Tomcat are affected by CVE-2020-11996?
Apache Tomcat versions 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35, and 8.5.0 to 8.5.55 are affected by CVE-2020-11996.
How severe is CVE-2020-11996?
CVE-2020-11996 has a severity rating of high.
Where can I find more information about CVE-2020-11996?
You can find more information about CVE-2020-11996 on the Apache Tomcat website.