CVE-2019-0197 Details
Description
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https: and did not set "H2Upgrade on" are unaffected by this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache http server | >= 2.4.34, <= 2.4.38 |
CPE
Remediation
| |
| canonical ubuntu linux | 16.04 18.04 19.04 |
CPE
Remediation
| |
| fedoraproject fedora | 30 |
CPE
Remediation
| |
| opensuse leap | 15.0 42.3 |
CPE
Remediation
| |
| redhat jboss core services | 1.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 |
CPE
Remediation
| |
| oracle communications session report manager | 8.0.0 8.1.0 8.1.1 8.2.0 |
CPE
Remediation
| |
| oracle communications session route manager | 8.0.0 8.1.0 8.1.1 8.2.0 |
CPE
Remediation
| |
| oracle enterprise manager ops center | 12.3.3 12.4.0 |
CPE
Remediation
| |
| oracle http server | 12.2.1.3.0 |
CPE
Remediation
| |
| oracle instantis enterprisetrack | 17.1 17.2 17.3 |
CPE
Remediation
| |
| oracle retail xstore point of service | 7.0 7.1 |
CPE
Remediation
| |
Change History
19 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Sep 7, 2022 | Modified Analysis | [email protected] |
| Jun 6, 2021 | CVE Modified | [email protected] |
| Mar 30, 2021 | CVE Modified | [email protected] |
| Apr 15, 2020 | CVE Modified | [email protected] |
| Apr 1, 2020 | CVE Modified | [email protected] |
| Apr 1, 2020 | CVE Modified | [email protected] |
| Nov 20, 2019 | CVE Modified | [email protected] |
| Nov 20, 2019 | CVE Modified | [email protected] |
| Oct 16, 2019 | CVE Modified | [email protected] |
| Aug 30, 2019 | CVE Modified | [email protected] |
| Aug 22, 2019 | CVE Modified | [email protected] |
| Aug 15, 2019 | CVE Modified | [email protected] |
| Jul 23, 2019 | CVE Modified | [email protected] |
| Jun 17, 2019 | CVE Modified | [email protected] |
| Jun 13, 2019 | Initial Analysis | [email protected] |