← Back

CVE-2019-17569

nvd nist
Published: Feb 24, 2020Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.2 / Impact: 2.5
Source: NVD

Description

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

Affected (25)

Show all products
2 products
Tomcat
Tomee
1 product
Leap
2 products
Data Availability Services
Oncommand System Manager
1 product
Debian Linux
10 products
Agile Engineering Data Management
Agile Plm
Health Sciences Empirica Signal
Hospitality Guest Access
Instantis Enterprisetrack
Mysql Enterprise Monitor
Transportation Management
Workload Manager
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 7.0.98 to 7.0.99
From 8.5.48 to 8.5.50
From 9.0.28 to 9.0.30
Version 7.0.7
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
From 3.0.0 to 3.1.3
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration E
16 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.2.1.0
Oracle
Version 9.3.3
Version 9.3.5
Version 9.3.6
Version 10.0.1.4.0
Version 1.0.1.2
Version 7.3.3
Oracle
Version 4.2.0
Version 4.2.1
From 17.1 to 17.3
Oracle
Up to 4.0.12
From 8.0.0 to 8.0.20
Version 6.3.7
Oracle
Version 12.2.0.1
Version 18c
Version 19c

References (22)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.