CVE-2019-17569
4.8
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.2 / Impact: 2.5
Source: NVD
Description
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Affected (25)
Products: Apache: Tomcat, Tomee · Opensuse: Leap · Netapp: Data Availability Services, Oncommand System Manager · +2 more
Show all products
Apache: Tomcat, Tomee · Opensuse: Leap · Netapp: Data Availability Services, Oncommand System Manager · Debian: Debian Linux · Oracle: Agile Engineering Data Management, Agile Plm, Communications Instant Messaging Server, Health Sciences Empirica Inspections, Health Sciences Empirica Signal, Hospitality Guest Access, Instantis Enterprisetrack, Mysql Enterprise Monitor, Transportation Management, Workload Manager
Configuration A
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| From 3.0.0 to 3.1.3 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2.1.0 | |
| Version 9.3.3 | |
| Version 10.0.1.4.0 | |
| Version 1.0.1.2 | |
| Version 7.3.3 | |
| Version 4.2.0 | |
| From 17.1 to 17.3 | |
| Up to 4.0.12 | |
| Version 6.3.7 | |
| Version 12.2.0.1 |
References (22)
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.