5.8
CVE-2020-1935
- EPSS 9.39%
- Veröffentlicht 24.02.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:38
- Erkennungen
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Netapp ≫ Data Availability Services Version -
Netapp ≫ Oncommand System Manager Version >= 3.0.0 <= 3.1.3
Oracle ≫ Agile Engineering Data Management Version 6.2.1.0
Oracle ≫ Agile Product Lifecycle Management Version 9.3.3
Oracle ≫ Agile Product Lifecycle Management Version 9.3.5
Oracle ≫ Agile Product Lifecycle Management Version 9.3.6
Oracle ≫ Communications Element Manager Version 8.1.1
Oracle ≫ Communications Element Manager Version 8.2.0
Oracle ≫ Communications Element Manager Version 8.2.1
Oracle ≫ Communications Instant Messaging Server Version 10.0.1.4.0
Oracle ≫ Health Sciences Empirica Inspections Version 1.0.1.2
Oracle ≫ Health Sciences Empirica Signal Version 7.3.3
Oracle ≫ Hospitality Guest Access Version 4.2.0
Oracle ≫ Hospitality Guest Access Version 4.2.1
Oracle ≫ Hyperion Infrastructure Technology Version 11.1.2.4
Oracle ≫ Instantis Enterprisetrack Version >= 17.1 <= 17.3
Oracle ≫ Mysql Enterprise Monitor Version >= 4.0.0 <= 4.0.12
Oracle ≫ Mysql Enterprise Monitor Version >= 8.0.0 <= 8.0.20
Oracle ≫ Retail Order Broker Version 15.0
Oracle ≫ Siebel Ui Framework Version <= 20.5
Oracle ≫ Transportation Management Version 6.3.7
Oracle ≫ Workload Manager Version 12.2.0.1
Oracle ≫ Workload Manager Version 18c
Oracle ≫ Workload Manager Version 19c
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.39% | 0.948 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.8 | 2.2 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.debian.org/security/2020/dsa-4680
https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html
https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E
https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html
https://security.netapp.com/advisory/ntap-20200327-0005/
https://www.debian.org/security/2020/dsa-4673
https://lists.apache.org/thread.html/r127f76181aceffea2bd4711b03c595d0f115f63e020348fe925a916c%40%3Cannounce.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r441c1f30a252bf14b07396286f6abd8089ce4240e91323211f1a2d75%40%3Cusers.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r660cd379afe346f10d72c0eaa8459ccc95d83aff181671b7e9076919%40%3Cusers.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r80e9c8417c77d52c62809168b96912bda70ddf7748f19f8210f745b1%40%3Cusers.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r9ce7918faf347e7aac32be930bf26c233b0b140fe37af0bb294158b6%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/ra5dee390ad2d60307b8362505c059cd6a726de4d146d63dfce1e05e7%40%3Cusers.tomcat.apache.org%3E
https://lists.apache.org/thread.html/rd547be0c9d821b4b1000a694b8e58ef9f5e2d66db03a31dfe77c4b18%40%3Cusers.tomcat.apache.org%3E
https://usn.ubuntu.com/4448-1/