CVE-2019-0197

MEDIUMCVSS 4.2/10EPSS 8.44%

Last modified

CVE-2019-0197 is a medium-severity vulnerability rated 4.2/10 on the CVSS scale. A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. EPSS estimates a 8.44% chance of exploitation in the next 30 days.

Description

A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https: and did not set "H2Upgrade on" are unaffected by this issue.

Metrics

CVSS 3.1
4.2/10

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

EPSS Probability
8.44%

94.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ApacheHttp Server>= 2.4.34, <= 2.4.38
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux18.04
CanonicalUbuntu Linux19.04
FedoraprojectFedora30
OpensuseLeap15.0
OpensuseLeap42.3
RedhatJboss Core Services1.0
OracleCommunications Session Report Manager8.0.0
OracleCommunications Session Report Manager8.1.0
OracleCommunications Session Report Manager8.1.1
OracleCommunications Session Report Manager8.2.0
OracleCommunications Session Route Manager8.0.0
OracleCommunications Session Route Manager8.1.0
OracleCommunications Session Route Manager8.1.1
OracleCommunications Session Route Manager8.2.0
OracleEnterprise Manager Ops Center12.3.3
OracleEnterprise Manager Ops Center12.4.0
OracleHttp Server12.2.1.3.0
OracleInstantis Enterprisetrack17.1
OracleInstantis Enterprisetrack17.2
OracleInstantis Enterprisetrack17.3
OracleRetail Xstore Point Of Service7.0
OracleRetail Xstore Point Of Service7.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-0197?
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https: and did not set "H2Upgrade on" are unaffected by this issue.
How severe is CVE-2019-0197?
CVE-2019-0197 has a CVSS score of 4.2/10 (MEDIUM severity). The EPSS model estimates a 8.44% probability of exploitation in the next 30 days.
How do I fix CVE-2019-0197?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-0197?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST