Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
CVSS Details
- CVSS 3.1 Base Score: 3.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to 5.0.0Upgrade Apache Tomcat to 5.5.23Upgrade Apache Tomcat to 6.0.11Upgrade Apache Tomcat to 4.1.36Upgrade Apache Tomcat to the latest available version | May 17, 2012 | Jun 30, 2005 |
| Apple Osx Tomcat | — | Apply OS X security update 2007-007 | Dec 16, 2011 | Jul 5, 2005 |
| Freebsd | — | Upgrade jakarta-tomcatUpgrade apache-tomcatUpgrade tomcat | Dec 10, 2025 | Jul 24, 2007 |
| Oracle Solaris | — | Upgrade web/java-servlet/tomcat/tomcat-examples to version 6.0.39-0.175.1.19.0.2.0 on Solaris 11.1Upgrade web/java-servlet/tomcat to version 6.0.39-0.175.1.19.0.2.0 on Solaris 11.1 | May 29, 2017 | Jul 5, 2005 |
| Oracle_linux | — | Upgrade tomcat5-webappsUpgrade tomcat5-jsp-2.0-api-javadocUpgrade tomcat5-server-libUpgrade tomcat5-jasperUpgrade tomcat5Upgrade tomcat5-servlet-2.4-apiUpgrade tomcat5-jasper-javadocUpgrade jakarta-commons-modelerUpgrade jakarta-commons-modeler-javadocUpgrade tomcat5-common-libUpgrade tomcat5-servlet-2.4-api-javadocUpgrade tomcat5-jsp-2.0-apiUpgrade tomcat5-admin-webapps | Oct 16, 2024 | Jun 30, 2005 |
| Suse | — | Upgrade tomcat5Upgrade jakarta-tomcat-docUpgrade suse-releaseUpgrade jakarta-tomcatUpgrade tomcat5-admin-webappsUpgrade tomcat5-webappsUpgrade apache2-jakarta-tomcat-connectorsUpgrade apache-jakarta-tomcat-connectorsUpgrade apache2-mod_jkUpgrade jakarta-tomcat-examples | Feb 17, 2015 | Jul 5, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub