HTTP2: Apache Tomcat HTTP2 Connection Window Exhaustion Denial of Service

This signature detects attempts to exploit a known vulnerability against HTTP/2 module of Apache Tomcat. A successful attack can result in a denial-of-service condition.

Extended Description

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

Affected Products

Apache tomcat

References

BugTraq: 108874

CVE: CVE-2019-10072

Short Name
HTTP2:APACHE-TOMCAT-DOS
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP2
Keywords
Apache CVE-2019-10072 Connection Denial Exhaustion HTTP2 Service Tomcat Window bid:108874 of
Release Date
07/15/2019
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Apache

CVSS Score

5.0

Found a potential security threat?