CVE-2019-9517

Description

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
4.564

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Node.js 12 (12.22.12)Windows
Multiple vulnerabilities are fixed in Node.js 18 (x64) (18.16.1)Windows
Multiple vulnerabilities are fixed in Node.js 18 (18.16.1)Windows
Multiple vulnerabilities are fixed in Node.js (x64) (10.16.3)Windows
Multiple vulnerabilities are fixed in Node.js (10.16.3)Windows
Multiple vulnerabilities are fixed in Node.js 8 8.16.1Windows
Multiple vulnerabilities are fixed in Node.js 8 (x64) 8.16.1Windows
Multiple vulnerabilities are fixed in Node.js 12 12.8.1Windows
Vulnerabilities CVE-2019-9517,CVE-2019-10081 are fixed in Apache 2.4.41Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.1Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.6.5Windows
Multiple Vulnerabilities are affected in IBM MQ 9.1Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.7Windows
apache2 security update(DSA-4509-1) apache2_2.4.25-3+deb9u8_i386.debLinux
apache2 security update(DSA-4509-1) apache2_2.4.25-3+deb9u8_amd64.debLinux
apache2 security update(DSA-4509-1) apache2_2.4.38-3+deb10u1_amd64.debLinux
Apache HTTP server (USN-4113-1) apache2_2.4.38-2ubuntu2.2_i386.debLinux
Apache HTTP server (USN-4113-1) apache2_2.4.38-2ubuntu2.2_amd64.debLinux
Apache HTTP server (USN-4113-1) apache2_2.4.18-2ubuntu3.12_i386.debLinux
Apache HTTP server (USN-4113-1) apache2_2.4.18-2ubuntu3.12_amd64.debLinux
Apache HTTP server (USN-4113-1) apache2_2.4.29-1ubuntu4.10_i386.debLinux
Apache HTTP server (USN-4113-1) apache2_2.4.29-1ubuntu4.10_amd64.debLinux
Apache HTTP server (USN-4113-1) apache2-bin_2.4.38-2ubuntu2.2_i386.debLinux
Apache HTTP server (USN-4113-1) apache2-bin_2.4.38-2ubuntu2.2_amd64.debLinux
Apache HTTP server (USN-4113-1) apache2-bin_2.4.18-2ubuntu3.12_i386.debLinux
Apache HTTP server (USN-4113-1) apache2-bin_2.4.18-2ubuntu3.12_amd64.debLinux
Apache HTTP server (USN-4113-1) apache2-bin_2.4.29-1ubuntu4.10_i386.debLinux
Apache HTTP server (USN-4113-1) apache2-bin_2.4.29-1ubuntu4.10_amd64.debLinux
SUSE-SU-2019:2329-1(SUSE Linux Enterprise Server 12-SP4 ) apache2-2.4.23-29.43.1.x86_64.rpmLinux
SUSE-SU-2019:2329-1(SUSE Linux Enterprise Server 12-SP4 ) apache2-debuginfo-2.4.23-29.43.1.x86_64.rpmLinux
SUSE-SU-2019:2329-1(SUSE Linux Enterprise Server 12-SP4 ) apache2-debugsource-2.4.23-29.43.1.x86_64.rpmLinux
SUSE-SU-2019:2329-1(SUSE Linux Enterprise Server 12-SP4 ) apache2-doc-2.4.23-29.43.1.noarch.rpmLinux
SUSE-SU-2019:2329-1(SUSE Linux Enterprise Server 12-SP4 ) apache2-example-pages-2.4.23-29.43.1.x86_64.rpmLinux
SUSE-SU-2019:2329-1(SUSE Linux Enterprise Server 12-SP4 ) apache2-prefork-2.4.23-29.43.1.x86_64.rpmLinux
SUSE-SU-2019:2329-1(SUSE Linux Enterprise Server 12-SP4 ) apache2-prefork-debuginfo-2.4.23-29.43.1.x86_64.rpmLinux
SUSE-SU-2019:2329-1(SUSE Linux Enterprise Server 12-SP4 ) apache2-utils-2.4.23-29.43.1.x86_64.rpmLinux
SUSE-SU-2019:2329-1(SUSE Linux Enterprise Server 12-SP4 ) apache2-utils-debuginfo-2.4.23-29.43.1.x86_64.rpmLinux
SUSE-SU-2019:2329-1(SUSE Linux Enterprise Server 12-SP4 ) apache2-worker-2.4.23-29.43.1.x86_64.rpmLinux
SUSE-SU-2019:2329-1(SUSE Linux Enterprise Server 12-SP4 ) apache2-worker-debuginfo-2.4.23-29.43.1.x86_64.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update httpd-2.4.37-12.module+el8.0.0+4096+eb40e6da.x86_64.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update httpd-debugsource-2.4.37-12.module+el8.0.0+4096+eb40e6da.x86_64.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update httpd-devel-2.4.37-12.module+el8.0.0+4096+eb40e6da.x86_64.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update httpd-filesystem-2.4.37-12.module+el8.0.0+4096+eb40e6da.noarch.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update httpd-manual-2.4.37-12.module+el8.0.0+4096+eb40e6da.noarch.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update httpd-tools-2.4.37-12.module+el8.0.0+4096+eb40e6da.x86_64.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update mod_http2-1.11.3-3.module+el8.0.0+4096+eb40e6da.x86_64.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update mod_http2-debugsource-1.11.3-3.module+el8.0.0+4096+eb40e6da.x86_64.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update mod_ldap-2.4.37-12.module+el8.0.0+4096+eb40e6da.x86_64.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update mod_md-2.4.37-12.module+el8.0.0+4096+eb40e6da.x86_64.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update mod_proxy_html-2.4.37-12.module+el8.0.0+4096+eb40e6da.x86_64.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update mod_session-2.4.37-12.module+el8.0.0+4096+eb40e6da.x86_64.rpmLinux
(RHSA-2019:2893) httpd:2.4 security update mod_ssl-2.4.37-12.module+el8.0.0+4096+eb40e6da.x86_64.rpmLinux
Mod_md update (ELSA-2019-2893) mod_md-2.4.37-12.0.1.module+el8.0.0+5348+de75177e.x86_64.rpmLinux
Httpd update (ELSA-2024-3121) httpd-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpmLinux
Httpd-devel update (ELSA-2024-3121) httpd-devel-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpmLinux
Httpd-filesystem update (ELSA-2024-3121) httpd-filesystem-2.4.37-64.module+el8.10.0+90271+3bc76a16.noarch.rpmLinux
Httpd-manual update (ELSA-2024-3121) httpd-manual-2.4.37-64.module+el8.10.0+90271+3bc76a16.noarch.rpmLinux
Httpd-tools update (ELSA-2024-3121) httpd-tools-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpmLinux
Mod_http2 update (ELSA-2024-3121) mod_http2-1.15.7-10.module+el8.10.0+90327+96b8ea28.x86_64.rpmLinux
Mod_ldap update (ELSA-2024-3121) mod_ldap-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpmLinux
Mod_md update (ELSA-2024-3121) mod_md-2.0.8-8.module+el8.9.0+90011+2f9c6a23.x86_64.rpmLinux
Mod_proxy_html update (ELSA-2024-3121) mod_proxy_html-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpmLinux
Mod_session update (ELSA-2024-3121) mod_session-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpmLinux
Mod_ssl update (ELSA-2024-3121) mod_ssl-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpmLinux
Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9517)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-324370Node.js 12 (12.22.12)
PATCH-331763Node.js 18 (x64) (18.17.0)
PATCH-331762Node.js 18 (18.17.0)
PATCH-319043Node.js 10 (x64) (10.24.1)
PATCH-319042Node.js 10 (10.24.1)
PATCH-324370Node.js 12 (12.22.12)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234