CVE-2020-11996: High severity IBM Data Risk Manager vulnerability
A specially crafted sequence of HTTP/2 requests could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
Reference: https://tomcat.apache.org/security-8.html
Other sources
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
Apache Tomcat is vulnerable to a denial of service. By sending a specially crafted sequence of HTTP/2 requests, a remote attacker could exploit this vulnerability to trigger high CPU usage for several seconds.
— IBM
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-11996?
CVE-2020-11996 is a vulnerability in Apache Tomcat that could trigger high CPU usage and make the server unresponsive.
How does CVE-2020-11996 impact Apache Tomcat?
CVE-2020-11996 can cause high CPU usage in Apache Tomcat and make the server unresponsive.
Which versions of Apache Tomcat are affected by CVE-2020-11996?
Apache Tomcat versions 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35, and 8.5.0 to 8.5.55 are affected by CVE-2020-11996.
How severe is CVE-2020-11996?
CVE-2020-11996 has a severity rating of high.
Where can I find more information about CVE-2020-11996?
You can find more information about CVE-2020-11996 on the Apache Tomcat website.