5.8

CVE-2020-1935

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 7.0.0 <= 7.0.99
Apache ≫ Tomcat Version >= 8.5.0 <= 8.5.50
Apache ≫ Tomcat Version >= 9.0.0 <= 9.0.30
Apache ≫ Tomcat Version 9.0.0 Update -
Apache ≫ Tomcat Version 9.0.0 Update milestone1
Apache ≫ Tomcat Version 9.0.0 Update milestone10
Apache ≫ Tomcat Version 9.0.0 Update milestone11
Apache ≫ Tomcat Version 9.0.0 Update milestone12
Apache ≫ Tomcat Version 9.0.0 Update milestone13
Apache ≫ Tomcat Version 9.0.0 Update milestone14
Apache ≫ Tomcat Version 9.0.0 Update milestone15
Apache ≫ Tomcat Version 9.0.0 Update milestone16
Apache ≫ Tomcat Version 9.0.0 Update milestone17
Apache ≫ Tomcat Version 9.0.0 Update milestone18
Apache ≫ Tomcat Version 9.0.0 Update milestone19
Apache ≫ Tomcat Version 9.0.0 Update milestone2
Apache ≫ Tomcat Version 9.0.0 Update milestone20
Apache ≫ Tomcat Version 9.0.0 Update milestone21
Apache ≫ Tomcat Version 9.0.0 Update milestone22
Apache ≫ Tomcat Version 9.0.0 Update milestone23
Apache ≫ Tomcat Version 9.0.0 Update milestone24
Apache ≫ Tomcat Version 9.0.0 Update milestone25
Apache ≫ Tomcat Version 9.0.0 Update milestone26
Apache ≫ Tomcat Version 9.0.0 Update milestone27
Apache ≫ Tomcat Version 9.0.0 Update milestone3
Apache ≫ Tomcat Version 9.0.0 Update milestone4
Apache ≫ Tomcat Version 9.0.0 Update milestone5
Apache ≫ Tomcat Version 9.0.0 Update milestone6
Apache ≫ Tomcat Version 9.0.0 Update milestone7
Apache ≫ Tomcat Version 9.0.0 Update milestone8
Apache ≫ Tomcat Version 9.0.0 Update milestone9
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Opensuse ≫ Leap Version 15.1
Netapp ≫ Oncommand System Manager Version >= 3.0.0 <= 3.1.3
Oracle ≫ Hospitality Guest Access Version 4.2.0
Oracle ≫ Hospitality Guest Access Version 4.2.1
Oracle ≫ Instantis Enterprisetrack Version >= 17.1 <= 17.3
Oracle ≫ Mysql Enterprise Monitor Version >= 4.0.0 <= 4.0.12
Oracle ≫ Mysql Enterprise Monitor Version >= 8.0.0 <= 8.0.20
Oracle ≫ Retail Order Broker Version 15.0
Oracle ≫ Siebel Ui Framework Version <= 20.5
Oracle ≫ Transportation Management Version 6.3.7
Oracle ≫ Workload Manager Version 12.2.0.1
Oracle ≫ Workload Manager Version 18c
Oracle ≫ Workload Manager Version 19c
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.39% 0.948
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.8 2.2 2.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

https://www.oracle.com/security-alerts/cpujan2021.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
Third Party Advisory
https://www.debian.org/security/2020/dsa-4680
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html
Third Party Advisory
Broken Link
Mailing List
https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E
https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20200327-0005/
Third Party Advisory
https://www.debian.org/security/2020/dsa-4673
Third Party Advisory
https://lists.apache.org/thread.html/r127f76181aceffea2bd4711b03c595d0f115f63e020348fe925a916c%40%3Cannounce.tomcat.apache.org%3E
Vendor Advisory
Mailing List
https://lists.apache.org/thread.html/r441c1f30a252bf14b07396286f6abd8089ce4240e91323211f1a2d75%40%3Cusers.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r660cd379afe346f10d72c0eaa8459ccc95d83aff181671b7e9076919%40%3Cusers.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r80e9c8417c77d52c62809168b96912bda70ddf7748f19f8210f745b1%40%3Cusers.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r9ce7918faf347e7aac32be930bf26c233b0b140fe37af0bb294158b6%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/ra5dee390ad2d60307b8362505c059cd6a726de4d146d63dfce1e05e7%40%3Cusers.tomcat.apache.org%3E
https://lists.apache.org/thread.html/rd547be0c9d821b4b1000a694b8e58ef9f5e2d66db03a31dfe77c4b18%40%3Cusers.tomcat.apache.org%3E
https://usn.ubuntu.com/4448-1/
Third Party Advisory