PT-2019-3472 · Oracle+16 · Oracle Graalvm+30

Jake Miller

+3

·

Published

2019-08-12

·

Updated

2026-05-18

·

CVE-2019-9515

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Traffic Server versions (affected versions not specified) H2O versions (affected versions not specified) Node.js versions (affected versions not specified) SwiftNIO versions (affected versions not specified) Arista EOS versions (affected versions not specified) Arista CloudVision Portal versions (affected versions not specified) Arista Wi-Fi software versions (affected versions not specified) Ubuntu Linux versions (affected versions not specified) Debian Linux versions (affected versions not specified) F5 BIG-IP Local Traffic Manager versions (affected versions not specified) Fedora versions (affected versions not specified) McAfee Web Gateway versions (affected versions not specified) OpenSUSE Leap versions (affected versions not specified) Oracle GraalVM versions (affected versions not specified) Red Hat Enterprise Linux versions (affected versions not specified) Red Hat JBoss Core Services versions (affected versions not specified) Red Hat JBoss Enterprise Application Platform versions (affected versions not specified) Red Hat OpenShift Container Platform versions (affected versions not specified) Red Hat OpenShift Service Mesh versions (affected versions not specified) Red Hat OpenStack versions (affected versions not specified) Red Hat Quay versions (affected versions not specified) Red Hat Single Sign-On versions (affected versions not specified) Red Hat Software Collections versions (affected versions not specified) Synology DiskStation Manager versions (affected versions not specified) Synology SkyNAS versions (affected versions not specified) Synology VS960HD Firmware versions (affected versions not specified)
Description The issue is related to errors in the resource consumption control mechanism of the HTTP/2 protocol implementation in various software products. An attacker can exploit this by sending a stream of SETTINGS frames, potentially leading to a denial of service due to excessive CPU or memory consumption. The vulnerability can be exploited by continually sending data, causing affected components to consume large amounts of memory and potentially leading to an out-of-memory condition.
Recommendations For Apache Traffic Server, consider disabling the HTTP/2 protocol until a patch is available. For H2O, restrict access to the HTTP/2 implementation to minimize the risk of exploitation. For Node.js, avoid using the HTTP/2 protocol in affected versions until the issue is resolved. For SwiftNIO, consider disabling the HTTP/2 protocol until a patch is available. For Arista EOS, disable TerminAttr and OpenConfig services if they are not necessary. For Arista CloudVision Portal, restrict access to the ingest component in the CVP Backend. For Arista Wi-Fi software, disable the OpenConfig interface on Access Points unless explicitly needed. For all other affected products, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:2925
ALT-PU-2019-3050
ALT-PU-2020-2195
BDU:2019-03646
CESA-2019_2925
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2019-9515
DSA-4508-1
DSA-4520-1
MGASA-2020-0372
OPENSUSE-SU-2019:2114-1
OPENSUSE-SU-2019:2115-1
OPENSUSE-SU-2019_2114-1
OPENSUSE-SU-2019_2115-1
RHSA-2019:2796
RHSA-2019:2925
RHSA-2019:2939
RHSA-2019:2955
RHSA-2019:4018
RHSA-2019:4019
RHSA-2019:4020
RHSA-2019:4040
RHSA-2019:4041
RHSA-2019:4042
RHSA-2019_2925
RHSA-2024:5856
RLSA-2019:2925
SUSE-SU-2019:14246-1
SUSE-SU-2019:2254-1
SUSE-SU-2019:2259-1
SUSE-SU-2019:2260-1
SUSE-SU-2019_14246-1
SUSE-SU-2020:0059-1
USN-4308-1
USN-4866-1

Affected Products

Alt Linux
Almalinux
Apache Traffic Server
Arista Cloudvision Portal
Arista Eos
Arista Wi-Fi
Centos
Debian
F5 Big-Ip Local Traffic Manager
Fedora
H2O
Mcafee Web Gateway
Node.Js
Opensuse Leap
Oracle Graalvm
Red Hat
Red Hat Jboss Core Services
Red Hat Jboss Enterprise Application Platform
Red Hat Openshift Container Platform
Red Hat Openshift Service Mesh
Red Hat Openstack
Red Hat Quay
Red Hat Single Sign-On
Red Hat Software Collections
Rocky Linux
Suse
Swiftnio
Synology Diskstation Manager
Synology Skynas
Synology Vs960Hd Firmware
Ubuntu