Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2020-13934 Details
Description
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | >= 8.5.1, <= 8.5.56 >= 9.0.1, <= 9.0.36 9.0.0 milestone10 9.0.0 milestone11 9.0.0 milestone12 9.0.0 milestone13 9.0.0 milestone14 9.0.0 milestone15 9.0.0 milestone16 9.0.0 milestone17 9.0.0 milestone18 9.0.0 milestone19 9.0.0 milestone20 9.0.0 milestone21 9.0.0 milestone22 9.0.0 milestone23 9.0.0 milestone24 9.0.0 milestone25 9.0.0 milestone26 9.0.0 milestone27 9.0.0 milestone5 9.0.0 milestone6 9.0.0 milestone7 9.0.0 milestone8 9.0.0 milestone9 10.0.0 milestone1 10.0.0 milestone2 10.0.0 milestone3 10.0.0 milestone4 10.0.0 milestone5 10.0.0 milestone6 |
CPE
Remediation
| |
| debian debian linux | 9.0 10.0 |
CPE
Remediation
| |
| netapp oncommand system manager | >= 3.0.0, <= 3.1.3 |
CPE
Remediation
| |
| opensuse leap | 15.1 15.2 |
CPE
Remediation
| |
| canonical ubuntu linux | 20.04 |
CPE
Remediation
| |
| oracle agile engineering data management | 6.2.1.0 |
CPE
Remediation
| |
| oracle agile product lifecycle management | 9.3.3 9.3.5 9.3.6 |
CPE
Remediation
| |
| oracle communications instant messaging server | 10.0.1.5.0 |
CPE
Remediation
| |
| oracle fmw platform | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle instantis enterprisetrack | 17.1 17.2 17.3 |
CPE
Remediation
| |
| oracle managed file transfer | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle mysql enterprise monitor | <= 8.0.21 |
CPE
Remediation
| |
| oracle siebel ui framework | <= 20.12 |
CPE
Remediation
| |
| oracle workload manager | 12.2.0.1 18c 19c |
CPE
Remediation
| |
Change History
22 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 25, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 25, 2026 | CPE Deprecation Remap | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Mar 1, 2022 | Modified Analysis | [email protected] |
| Feb 7, 2022 | CVE Modified | [email protected] |
| Jul 21, 2021 | CWE Remap | [email protected] |
| Jul 20, 2021 | CVE Modified | [email protected] |
| Jun 14, 2021 | CVE Modified | [email protected] |
| Jan 20, 2021 | CVE Modified | [email protected] |
| Oct 27, 2020 | CVE Modified | [email protected] |
| Oct 20, 2020 | CVE Modified | [email protected] |
| Aug 18, 2020 | CVE Modified | [email protected] |
| Jul 29, 2020 | CVE Modified | [email protected] |
| Jul 28, 2020 | CVE Modified | [email protected] |
| Jul 24, 2020 | CVE Modified | [email protected] |
| Jul 22, 2020 | CVE Modified | [email protected] |
| Jul 18, 2020 | CVE Modified | [email protected] |
| Jul 17, 2020 | Initial Analysis | [email protected] |