5.8

CVE-2019-17569

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 7.0.98 <= 7.0.99
Apache ≫ Tomcat Version >= 8.5.48 <= 8.5.50
Apache ≫ Tomcat Version >= 9.0.28 <= 9.0.30
Apache ≫ Tomee Version 7.0.7
Opensuse ≫ Leap Version 15.1
Netapp ≫ Oncommand System Manager Version >= 3.0.0 <= 3.1.3
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Oracle ≫ Hospitality Guest Access Version 4.2.0
Oracle ≫ Hospitality Guest Access Version 4.2.1
Oracle ≫ Instantis Enterprisetrack Version >= 17.1 <= 17.3
Oracle ≫ Mysql Enterprise Monitor Version <= 4.0.12
Oracle ≫ Mysql Enterprise Monitor Version >= 8.0.0 <= 8.0.20
Oracle ≫ Transportation Management Version 6.3.7
Oracle ≫ Workload Manager Version 12.2.0.1
Oracle ≫ Workload Manager Version 18c
Oracle ≫ Workload Manager Version 19c
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.87% 0.945
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.8 2.2 2.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

https://www.oracle.com/security-alerts/cpujan2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
Patch
Third Party Advisory
https://www.debian.org/security/2020/dsa-4680
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20200327-0005/
Third Party Advisory
https://www.debian.org/security/2020/dsa-4673
Third Party Advisory
https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r88def002c5c78534674ca67472e035099fbe088813d50062094a1390%40%3Cannounce.tomcat.apache.org%3E
Vendor Advisory
Mailing List
https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E