HTTP2: Apache Tomcat HTTP2 Denial of Service

This signature detects attempts to exploit a known vulnerability against Apache Tomcat. A successful attack can result in a denial-of-service condition.

Extended Description

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for requests that utilised the Servlet API's blocking I/O, clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

Affected Products

Apache tomcat

Short Name
HTTP2:APACHE-CVE-2019-0199-DOS
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP2
Keywords
Apache CVE-2019-0199 Denial HTTP2 Service Tomcat of
Release Date
06/04/2019
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3552
False Positive
Unknown
Vendors

Apache

CVSS Score

5.0

Found a potential security threat?