CVE-2019-0199
high
CVSS v3
—
CVSS v2
—
VIR risk
8.0
Description
Apache Tomcat Denial of Service vulnerability
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2019-0199
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2019-0199.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | fixed | 9.0.16-1 |
| debian | bullseye | fixed | 9.0.16-1 |
| debian | forky | fixed | 9.0.16-1 |
| debian | sid | fixed | 9.0.16-1 |
| debian | trixie | fixed | 9.0.16-1 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.tomcat.embed:tomcat-embed-core | >=9.0.0,<9.0.16 | 9.0.16 |
| Maven | org.apache.tomcat.embed:tomcat-embed-core | >=8.0.0,<8.5.38 | 8.5.38 |
| Maven | org.apache.tomcat:tomcat-coyote | >=9.0.0,<9.0.16 | 9.0.16 |
| Maven | org.apache.tomcat:tomcat-coyote | >=8.0.0,<8.5.38 | 8.5.38 |
| MAVEN | org.apache.tomcat:tomcat-coyote | >= 8.0.0, < 8.5.38 | 8.5.38 |
| MAVEN | org.apache.tomcat:tomcat-coyote | >= 9.0.0, < 9.0.16 | 9.0.16 |
| MAVEN | org.apache.tomcat.embed:tomcat-embed-core | >= 8.0.0, < 8.5.38 | 8.5.38 |
| MAVEN | org.apache.tomcat.embed:tomcat-embed-core | >= 9.0.0, < 9.0.16 | 9.0.16 |
References
- https://www.suse.com/security/cve/CVE-2019-0199.html
- https://nvd.nist.gov/vuln/detail/CVE-2019-0199
- https://lists.apache.org/thread.html/e1b0b273b6e8ddcc72c9023bc2394b1276fc72664144bf21d0a87995@%3Cannounce.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/e56886e1bac9319ecce81b3612dd7a1a43174a3a741a1c805e16880e%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/e56886e1bac9319ecce81b3612dd7a1a43174a3a741a1c805e16880e@%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/e87733036e8c84ea648cdcdca3098f3c8a897e2652c33062b2b1535c%40%3Cusers.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/e87733036e8c84ea648cdcdca3098f3c8a897e2652c33062b2b1535c@%3Cusers.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPHQEL5AQ6LZSZD2Y6TYZ4RC3WI7NXJ3
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQTZ5BJ5F4KV6N53SGNKSW3UY5DBIQ46
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NPHQEL5AQ6LZSZD2Y6TYZ4RC3WI7NXJ3
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZQTZ5BJ5F4KV6N53SGNKSW3UY5DBIQ46
- https://seclists.org/bugtraq/2019/Dec/43
- https://security.netapp.com/advisory/ntap-20190419-0001
- https://support.f5.com/csp/article/K17321505
- https://web.archive.org/web/20200227030041/http://www.securityfocus.com/bid/107674
Verify integrity in audit chain (admin only). AS-IS.