5.3mediumMedium

CVE-2021-33037

Apache Tomcat

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
5.3 (v3.1)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-444
Assigned by
security@apache.org

Dates

Published
2021-07-12
Last modified
2026-08-25
Sources
NVD

Affected products

  • Apache Tomcat8.5.0 - 8.5.66, 9.0.0 - 9.0.46, 10.0.0 - 10.0.6
  • Apache Tomee8.0.6
  • Debian Debian Linux9.0, 10.0
  • Oracle Agile Product Lifecycle Management9.3.6
  • Oracle Communications Cloud Native Core Policy1.14.0
  • Oracle Communications Cloud Native Core Service Communication Proxy1.14.0
  • Oracle Communications Diameter Signaling Router8.0.0.0 - 8.5.0.2
  • Oracle Communications Instant Messaging Server10.0.1.5.0
  • Oracle Communications Policy Management12.5.0
  • Oracle Communications Pricing Design Center12.0.0.3.0
  • Oracle Communications Session Report Manager8.0.0 - 8.2.4.0
  • Oracle Communications Session Route Manager8.0.0 - 8.2.4

As listed in the NVD configuration data. Not a statement about your estate.

References