Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "8.2.0"
},
{
"last_affected": "8.2.2"
}
],
"source": "CPE_RANGE",
"vendor_product": "oracle:communications_element_manager",
"cpes": [
"cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"introduced": "8.2.0"
},
{
"last_affected": "8.2.2"
}
],
"vendor_product": "oracle:communications_session_report_manager",
"cpes": [
"cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"extracted_events": [
{
"introduced": "8.2.0"
},
{
"last_affected": "8.2.2"
}
],
"vendor_product": "oracle:communications_session_route_manager",
"cpes": [
"cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"extracted_events": [
{
"last_affected": "16.04"
},
{
"last_affected": "18.04"
},
{
"last_affected": "20.04"
}
],
"source": "CPE_STRING",
"vendor_product": "canonical:ubuntu_linux",
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "10.0"
}
],
"source": "CPE_STRING",
"vendor_product": "debian:debian_linux",
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "31"
},
{
"last_affected": "32"
}
],
"source": "CPE_STRING",
"vendor_product": "fedoraproject:fedora",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "15.1"
},
{
"last_affected": "15.2"
}
],
"source": "CPE_STRING",
"vendor_product": "opensuse:leap",
"cpes": [
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "12.4.0.0"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:enterprise_manager_ops_center",
"cpes": [
"cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "11.1.2.4"
}
],
"vendor_product": "oracle:hyperion_infrastructure_technology",
"cpes": [
"cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "17.1"
},
{
"last_affected": "17.2"
},
{
"last_affected": "17.3"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:instantis_enterprisetrack",
"cpes": [
"cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "8.8"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:zfs_storage_appliance_kit",
"cpes": [
"cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "8.0"
}
],
"source": "CPE_STRING",
"vendor_product": "redhat:enterprise_linux",
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "8.1"
},
{
"last_affected": "8.2"
},
{
"last_affected": "8.4"
},
{
"last_affected": "8.6"
}
],
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "redhat:enterprise_linux_eus"
},
{
"extracted_events": [
{
"last_affected": "8.0"
}
],
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "redhat:enterprise_linux_for_ibm_z_systems"
},
{
"extracted_events": [
{
"last_affected": "8.1"
},
{
"last_affected": "8.2"
},
{
"last_affected": "8.4"
},
{
"last_affected": "8.6"
}
],
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.1:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.2:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.6:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "redhat:enterprise_linux_for_ibm_z_systems_eus"
},
{
"extracted_events": [
{
"last_affected": "8.0"
}
],
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "redhat:enterprise_linux_for_power_little_endian"
},
{
"extracted_events": [
{
"last_affected": "8.1"
},
{
"last_affected": "8.2"
},
{
"last_affected": "8.4"
},
{
"last_affected": "8.6"
}
],
"source": "CPE_STRING",
"vendor_product": "redhat:enterprise_linux_for_power_little_endian_eus",
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.1:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.2:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "8.2"
},
{
"last_affected": "8.4"
},
{
"last_affected": "8.6"
}
],
"vendor_product": "redhat:enterprise_linux_server_aus",
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "8.1"
},
{
"last_affected": "8.2"
},
{
"last_affected": "8.4"
},
{
"last_affected": "8.6"
}
],
"source": "CPE_STRING",
"vendor_product": "redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions",
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.1:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.2:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.4:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "8.2"
},
{
"last_affected": "8.4"
},
{
"last_affected": "8.6"
}
],
"vendor_product": "redhat:enterprise_linux_server_tus",
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "8.1"
},
{
"last_affected": "8.2"
},
{
"last_affected": "8.4"
},
{
"last_affected": "8.6"
}
],
"vendor_product": "redhat:enterprise_linux_server_update_services_for_sap_solutions",
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.1:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.2:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.4:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "16.1"
}
],
"source": "CPE_STRING",
"vendor_product": "redhat:openstack",
"cpes": [
"cpe:2.3:a:redhat:openstack:16.1:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "16.1"
}
],
"cpes": [
"cpe:2.3:a:redhat:openstack_for_ibm_power:16.1:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "redhat:openstack_for_ibm_power"
},
{
"extracted_events": [
{
"last_affected": "1.0"
}
],
"source": "CPE_STRING",
"vendor_product": "redhat:software_collections",
"cpes": [
"cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*"
]
}
]
}