Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2020-13935

HIGH · 7.5 CVSS Gepubliceerd: CWE-835

Beschrijving

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.

Vendors

Apache Debian Netapp Opensuse Canonical Mcafee Oracle

Affected products

Tomcat Debian Linux Oncommand System Manager Leap Ubuntu Linux Epolicy Orchestrator Agile Engineering Data Management Agile Product Lifecycle Management Blockchain Platform Commerce Guided Search Communications Cloud Native Core Policy Communications Instant Messaging Server Fmw Platform Instantis Enterprisetrack Managed File Transfer Mysql Enterprise Monitor Siebel Ui Framework Workload Manager

References