4.8mediumMedium

CVE-2019-17569

Apache Tomcat

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
4.8 (v3.1)
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-444
Assigned by
security@apache.org

Dates

Published
2020-02-24
Last modified
2026-08-25
Sources
NVD

Affected products

  • Apache Tomcat7.0.98 - 7.0.99, 8.5.48 - 8.5.50, 9.0.28 - 9.0.30
  • Apache Tomee7.0.7
  • Opensuse Leap15.1
  • Netapp Data Availability Servicesall versions
  • Netapp Oncommand System Manager3.0.0 - 3.1.3
  • Debian Debian Linux9.0, 10.0
  • Oracle Agile Engineering Data Management6.2.1.0
  • Oracle Agile Product Lifecycle Management9.3.3, 9.3.5, 9.3.6
  • Oracle Communications Instant Messaging Server10.0.1.4.0
  • Oracle Health Sciences Empirica Inspections1.0.1.2
  • Oracle Health Sciences Empirica Signal7.3.3
  • Oracle Hospitality Guest Access4.2.0, 4.2.1

As listed in the NVD configuration data. Not a statement about your estate.

References