The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-webappsUpgrade tomcat-admin-webappsUpgrade tomcat-libUpgrade tomcat-javadocUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-servlet-3.1-apiUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-el-3.0-apiUpgrade tomcat-jsvc | Sep 28, 2023 | Feb 24, 2020 |
| Amazon_linux | — | Upgrade tomcat8Upgrade tomcat7 | Mar 14, 2020 | Feb 24, 2020 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 8.5.51Upgrade Apache Tomcat to 9.0.31Upgrade Apache Tomcat to 7.0.100Upgrade Apache Tomcat to the latest available version | Feb 24, 2020 | Feb 24, 2020 |
| Debian | — | Upgrade tomcat9 | Mar 6, 2020 | Feb 24, 2020 |
| Oracle Missing Cpu Jul 2020 | — | Apply the July 2020 Critical Patch Update (CPU) for Oracle Database | Jul 14, 2020 | Feb 24, 2020 |
| Oracle Solaris | — | Upgrade web/java-servlet/tomcat-8 to version 8.5.51-11.4.20.0.1.3.0 on Solaris 11.4Upgrade web/java-servlet/tomcat-8/tomcat-admin to version 8.5.51-11.4.20.0.1.3.0 on Solaris 11.4Upgrade web/java-servlet/tomcat-8/tomcat-admin to version 8.5.51-0.175.3.36.0.20.0 on Solaris 11.3Upgrade web/java-servlet/tomcat-8/tomcat-examples to version 8.5.51-11.4.20.0.1.3.0 on Solaris 11.4Upgrade web/java-servlet/tomcat-8/tomcat-examples to version 8.5.51-0.175.3.36.0.20.0 on Solaris 11.3Upgrade web/java-servlet/tomcat-8 to version 8.5.51-0.175.3.36.0.20.0 on Solaris 11.3 | Jan 19, 2021 | Feb 24, 2020 |
| Suse | — | Upgrade tomcat-servlet-3_1-apiUpgrade tomcat-javadocUpgrade tomcatUpgrade tomcat-docs-webappUpgrade tomcat-admin-webappsUpgrade tomcat-libUpgrade tomcat-embedUpgrade tomcat-el-3_0-apiUpgrade tomcat-jsvcUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-webappsUpgrade tomcat-jsp-2_3-api | Mar 6, 2020 | Feb 24, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub