7.5
CVE-2020-13934
- EPSS 64.12%
- Veröffentlicht 14.07.2020 15:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
- Erkennungen
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Netapp ≫ Oncommand System Manager Version >= 3.0.0 <= 3.1.3
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Oracle ≫ Agile Engineering Data Management Version 6.2.1.0
Oracle ≫ Agile Product Lifecycle Management Version 9.3.3
Oracle ≫ Agile Product Lifecycle Management Version 9.3.5
Oracle ≫ Agile Product Lifecycle Management Version 9.3.6
Oracle ≫ Communications Instant Messaging Server Version 10.0.1.5.0
Oracle ≫ Fmw Platform Version 12.2.1.3.0
Oracle ≫ Fmw Platform Version 12.2.1.4.0
Oracle ≫ Instantis Enterprisetrack Version 17.1
Oracle ≫ Instantis Enterprisetrack Version 17.2
Oracle ≫ Instantis Enterprisetrack Version 17.3
Oracle ≫ Managed File Transfer Version 12.2.1.3.0
Oracle ≫ Managed File Transfer Version 12.2.1.4.0
Oracle ≫ Mysql Enterprise Monitor Version <= 8.0.21
Oracle ≫ Siebel Ui Framework Version <= 20.12
Oracle ≫ Workload Manager Version 12.2.0.1
Oracle ≫ Workload Manager Version 18c
Oracle ≫ Workload Manager Version 19c
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 64.12% | 0.991 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-401 Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/security-alerts/cpuapr2021.html
https://usn.ubuntu.com/4596-1/
https://www.debian.org/security/2020/dsa-4727
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html
https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html
https://security.netapp.com/advisory/ntap-20200724-0003/
https://lists.apache.org/thread.html/r61f411cf82488d6ec213063fc15feeeb88e31b0ca9c29652ee4f962e%40%3Cannounce.tomcat.apache.org%3E
https://lists.apache.org/thread.html/ra072b1f786e7d139e86f1d1145572e0ff71cef38a96d9c6f5362aac8%40%3Cdev.tomcat.apache.org%3E