Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux

Apache Tomcat Multiple DoS Vulnerabilities - July20 (Windows)
Information
Severity
Severity
High
Family
Family
Denial of Service
CVSSv2 Base
CVSSv2 Base
7.8
CVSSv2 Vector
CVSSv2 Vector
AV:N/AC:L/Au:N/C:N/I:N/A:C
Solution Type
Solution Type
Vendor Patch
Created
Created
2 years ago
Modified
Modified
2 years ago
Summary
Apache Tomcat is prone to multiple denial of service vulnerabilities.
Insight
Insight
The following vulnerabilitities exist: - HTTP/2 Denial of Service (CVE-2020-13934) - WebSocket Denial of Service (CVE-2020-13935)
Affected Software
Affected Software
Apache Tomcat 8.5.1 to 8.5.56, 9.0.0.M5 to 9.0.36 and 10.0.0-M1 to 10.0.0-M6.
Detection Method
Detection Method
Checks if a vulnerable version is present on the target host.
Solution
Solution
Update to version 8.5.57, 9.0.37, 10.0.0-M7 or later.
Common Vulnerabilities and Exposures (CVE)
References
- https://lists.apache.org/thread.html/r61f411cf82488d6ec213063fc15feeeb
- https://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.0
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.3
- https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.5