5.8
CVE-2019-17569
- EPSS 8.87%
- Veröffentlicht 24.02.2020 22:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
- Erkennungen
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ Data Availability Services Version -
Netapp ≫ Oncommand System Manager Version >= 3.0.0 <= 3.1.3
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Oracle ≫ Agile Engineering Data Management Version 6.2.1.0
Oracle ≫ Agile Product Lifecycle Management Version 9.3.3
Oracle ≫ Agile Product Lifecycle Management Version 9.3.5
Oracle ≫ Agile Product Lifecycle Management Version 9.3.6
Oracle ≫ Communications Instant Messaging Server Version 10.0.1.4.0
Oracle ≫ Health Sciences Empirica Inspections Version 1.0.1.2
Oracle ≫ Health Sciences Empirica Signal Version 7.3.3
Oracle ≫ Hospitality Guest Access Version 4.2.0
Oracle ≫ Hospitality Guest Access Version 4.2.1
Oracle ≫ Instantis Enterprisetrack Version >= 17.1 <= 17.3
Oracle ≫ Mysql Enterprise Monitor Version <= 4.0.12
Oracle ≫ Mysql Enterprise Monitor Version >= 8.0.0 <= 8.0.20
Oracle ≫ Transportation Management Version 6.3.7
Oracle ≫ Workload Manager Version 12.2.0.1
Oracle ≫ Workload Manager Version 18c
Oracle ≫ Workload Manager Version 19c
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 8.87% | 0.945 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.8 | 2.2 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.debian.org/security/2020/dsa-4680
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html
https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html
https://security.netapp.com/advisory/ntap-20200327-0005/
https://www.debian.org/security/2020/dsa-4673
https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r88def002c5c78534674ca67472e035099fbe088813d50062094a1390%40%3Cannounce.tomcat.apache.org%3E
https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E