5.3
CVE-2021-33037
- EPSS 75.35%
- Veröffentlicht 12.07.2021 15:15:08
- Zuletzt bearbeitet 25.08.2026 16:28:27
- Erkennungen
Incorrect Transfer-Encoding handling with HTTP/1.0
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Oracle ≫ Agile Product Lifecycle Management Version 9.3.6
Oracle ≫ Communications Cloud Native Core Policy Version 1.14.0
Oracle ≫ Communications Cloud Native Core Service Communication Proxy Version 1.14.0
Oracle ≫ Communications Diameter Signaling Router Version >= 8.0.0.0 <= 8.5.0.2
Oracle ≫ Communications Instant Messaging Server Version 10.0.1.5.0
Oracle ≫ Communications Policy Management Version 12.5.0
Oracle ≫ Communications Pricing Design Center Version 12.0.0.3.0
Oracle ≫ Communications Session Report Manager Version >= 8.0.0 <= 8.2.4.0
Oracle ≫ Communications Session Route Manager Version >= 8.0.0 <= 8.2.4
Oracle ≫ Graph Server And Client Version < 21.4
Oracle ≫ Healthcare Translational Research Version 4.1.0
Oracle ≫ Hospitality Cruise Shipboard Property Management System Version 20.1.0
Oracle ≫ Instantis Enterprisetrack Version 17.1
Oracle ≫ Instantis Enterprisetrack Version 17.2
Oracle ≫ Instantis Enterprisetrack Version 17.3
Oracle ≫ Managed File Transfer Version 12.2.1.3.0
Oracle ≫ Managed File Transfer Version 12.2.1.4.0
Oracle ≫ Mysql Enterprise Monitor Version <= 8.0.25
Oracle ≫ Sd-wan Edge Version 9.0
Oracle ≫ Sd-wan Edge Version 9.1
Oracle ≫ Secure Global Desktop Version 5.6
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.1.1
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.2.2
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.3.1
Mcafee ≫ Epolicy Orchestrator Version < 5.10.0
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update -
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_1
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_10
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_2
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_3
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_4
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_5
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_6
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_7
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_8
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 75.35% | 0.995 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://security.gentoo.org/glsa/202208-34
https://security.netapp.com/advisory/ntap-20210827-0007/
https://lists.debian.org/debian-lts-announce/2021/08/msg00009.html
https://www.debian.org/security/2021/dsa-4952
https://kc.mcafee.com/corporate/index?page=content&id=SB10366
https://lists.apache.org/thread.html/r290aee55b72811fd19e75ac80f6143716c079170c5671b96932ed44b%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r40f921575aee8d7d34e53182f862c45cbb8f3d898c9d4e865c2ec262%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/r612a79269b0d5e5780c62dfd34286a8037232fec0bc6f1a7e60c9381%40%3Cannounce.tomcat.apache.org%3E
https://lists.apache.org/thread.html/rc6ef52453bb996a98cb45442871a1db56b7c349939e45d829bf9ae37%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/rd0dfea39829bc0606c936a16f6fca338127c86c0a1083970b45ac8d2%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/re01e7e93154e8bdf78a11a23f9686427bd3d51fc6e12c508645567b7%40%3Ccommits.tomee.apache.org%3E
https://lists.apache.org/thread.html/rf1b54fd3f52f998ca4829159a88cc4c23d6cef5c6447d00948e75c97%40%3Ccommits.tomee.apache.org%3E