VDB
RHSA-2020:3197
RHSA-2020:3197
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in HTTP/2. Using PING frames and queuing of response PING ACK frames, a flood attack could occur resulting in unbounded memory growth. The highest threat from this vulnerability is to system availability.
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Process Automation 7 |
Timeline
- Jul 29, 2020 CVE Published
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2020:3197 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=rhpam&version=7.8.0 advisory
- https://access.redhat.com/documentation/en-us/red_hat_process_automation_manager/7.8/html/release_notes_for_red_hat_process_automation_manager_7.8/index advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1735745 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1735749 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1797011 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1798509 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1816170 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1816216 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1819212 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1821315 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1826798 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1826805 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1848960 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1848962 issue
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md advisory
- https://access.redhat.com/security/cve/CVE-2019-9514 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-9514 advisory
- https://access.redhat.com/security/cve/CVE-2019-9515 advisory
…and 124 more