7.5

CVE-2020-13935

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 7.0.27 <= 7.0.104
Apache ≫ Tomcat Version >= 8.5.0 <= 8.5.56
Apache ≫ Tomcat Version >= 9.0.1 <= 9.0.36
Apache ≫ Tomcat Version 9.0.0 Update milestone1
Apache ≫ Tomcat Version 9.0.0 Update milestone10
Apache ≫ Tomcat Version 9.0.0 Update milestone11
Apache ≫ Tomcat Version 9.0.0 Update milestone12
Apache ≫ Tomcat Version 9.0.0 Update milestone13
Apache ≫ Tomcat Version 9.0.0 Update milestone14
Apache ≫ Tomcat Version 9.0.0 Update milestone15
Apache ≫ Tomcat Version 9.0.0 Update milestone16
Apache ≫ Tomcat Version 9.0.0 Update milestone17
Apache ≫ Tomcat Version 9.0.0 Update milestone18
Apache ≫ Tomcat Version 9.0.0 Update milestone19
Apache ≫ Tomcat Version 9.0.0 Update milestone2
Apache ≫ Tomcat Version 9.0.0 Update milestone20
Apache ≫ Tomcat Version 9.0.0 Update milestone21
Apache ≫ Tomcat Version 9.0.0 Update milestone22
Apache ≫ Tomcat Version 9.0.0 Update milestone23
Apache ≫ Tomcat Version 9.0.0 Update milestone24
Apache ≫ Tomcat Version 9.0.0 Update milestone25
Apache ≫ Tomcat Version 9.0.0 Update milestone26
Apache ≫ Tomcat Version 9.0.0 Update milestone27
Apache ≫ Tomcat Version 9.0.0 Update milestone3
Apache ≫ Tomcat Version 9.0.0 Update milestone4
Apache ≫ Tomcat Version 9.0.0 Update milestone5
Apache ≫ Tomcat Version 9.0.0 Update milestone6
Apache ≫ Tomcat Version 9.0.0 Update milestone7
Apache ≫ Tomcat Version 9.0.0 Update milestone8
Apache ≫ Tomcat Version 9.0.0 Update milestone9
Apache ≫ Tomcat Version 10.0.0 Update milestone1
Apache ≫ Tomcat Version 10.0.0 Update milestone2
Apache ≫ Tomcat Version 10.0.0 Update milestone3
Apache ≫ Tomcat Version 10.0.0 Update milestone4
Apache ≫ Tomcat Version 10.0.0 Update milestone5
Apache ≫ Tomcat Version 10.0.0 Update milestone6
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Netapp ≫ Oncommand System Manager Version >= 3.0.0 <= 3.1.3
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 15.2
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Mcafee ≫ Epolicy Orchestrator Version 5.9.0
Mcafee ≫ Epolicy Orchestrator Version 5.9.1
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update -
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_1
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_2
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_3
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_4
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_5
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_6
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_7
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_8
Oracle ≫ Blockchain Platform Version < 21.1.2
Oracle ≫ Commerce Guided Search Version 11.3.2
Oracle ≫ Fmw Platform Version 12.2.1.3.0
Oracle ≫ Fmw Platform Version 12.2.1.4.0
Oracle ≫ Managed File Transfer Version 12.2.1.3.0
Oracle ≫ Managed File Transfer Version 12.2.1.4.0
Oracle ≫ Mysql Enterprise Monitor Version <= 8.0.21
Oracle ≫ Siebel Ui Framework Version <= 20.12
Oracle ≫ Workload Manager Version 12.2.0.1
Oracle ≫ Workload Manager Version 18c
Oracle ≫ Workload Manager Version 19c
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 86.61% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

https://www.oracle.com/security-alerts/cpujan2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Patch
Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Third Party Advisory
Not Applicable
https://www.oracle.com/security-alerts/cpuoct2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2021.html
Patch
Third Party Advisory
https://usn.ubuntu.com/4448-1/
Third Party Advisory
https://usn.ubuntu.com/4596-1/
Third Party Advisory
https://www.debian.org/security/2020/dsa-4727
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20200724-0003/
Third Party Advisory
https://kc.mcafee.com/corporate/index?page=content&id=SB10332
Third Party Advisory
https://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50%40%3Cusers.tomcat.apache.org%3E
https://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c074d94f8a701f93b85752651%40%3Cannounce.tomcat.apache.org%3E
Vendor Advisory
Mailing List
Release Notes