Learn about CVE-2019-0199 affecting Apache Tomcat versions 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37. Understand the DoS vulnerability, its impact, and mitigation steps.
Apache Tomcat versions 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 were affected by a flaw in the HTTP/2 implementation, leading to a Denial of Service (DoS) vulnerability.
Understanding CVE-2019-0199
This CVE entry pertains to a vulnerability in Apache Tomcat versions 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 that allowed for a DoS attack.
What is CVE-2019-0199?
The flaw in the HTTP/2 implementation in Apache Tomcat versions 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 enabled clients to keep streams open without reading or writing data, causing server-side threads to block and leading to thread exhaustion and a DoS.
The Impact of CVE-2019-0199
The vulnerability allowed malicious clients to exhaust server-side threads, resulting in a DoS condition that could disrupt the availability of the affected Apache Tomcat servers.
Technical Details of CVE-2019-0199
Apache Tomcat's vulnerability to a DoS attack through the HTTP/2 implementation.
Vulnerability Description
The flaw in Apache Tomcat versions 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 allowed clients to keep streams open without reading or writing data, leading to thread exhaustion and a DoS.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Steps to address and prevent the CVE-2019-0199 vulnerability.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates