CVE-2019-17569
published 2020-02-24CVE-2019-17569: The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that…
PriorityP430medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
8.87%
94.6th percentile
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_tomcat | — | — |
| apache | apache_tomcat | — | — |
| apache | apache_tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | 7.0.98 – 7.0.99 | — |
| apache | tomcat | 8.5.48 – 8.5.50 | — |
| apache | tomcat | 9.0.28 – 9.0.30 | — |
| apache | tomee | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.31-1 (bookworm) | tomcat9 9.0.31-1 (bookworm) |
| netapp | oncommand_system_manager | 3.0.0 – 3.1.3 | — |
| opensuse | leap | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
| oracle | communications_instant_messaging_server | — | — |
| oracle | health_sciences_empirica_inspections | — | — |
| oracle | health_sciences_empirica_signal | — | — |
| oracle | hospitality_guest_access | — | — |
| oracle | hospitality_guest_access | — | — |
| oracle | instantis_enterprisetrack | 17.1 – 17.3 | — |
| oracle | mysql_enterprise_monitor | <= 4.0.12 | — |
| oracle | mysql_enterprise_monitor | 8.0.0 – 8.0.20 | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv4.8MEDIUM
vendor_apache4.8MEDIUM
vendor_debian4.8MEDIUM
vendor_oracle4.8MEDIUM
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Potential HTTP request smuggling in Apache Tomcat
ghsa·2020-02-28
CVE-2019-17569 [MEDIUM] CWE-444 Potential HTTP request smuggling in Apache Tomcat
Potential HTTP request smuggling in Apache Tomcat
The refactoring present in Apache Tomcat versions 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
OSV
Potential HTTP request smuggling in Apache Tomcat
osv·2020-02-28
CVE-2019-17569 [MEDIUM] Potential HTTP request smuggling in Apache Tomcat
Potential HTTP request smuggling in Apache Tomcat
The refactoring present in Apache Tomcat versions 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
OSV
CVE-2019-17569: The refactoring present in Apache Tomcat 9
osv·2020-02-24·CVSS 4.8
CVE-2019-17569 [MEDIUM] CVE-2019-17569: The refactoring present in Apache Tomcat 9
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Oracle
Oracle Oracle Database Server Risk Matrix: Workload Manager (Apache Tomcat) — CVE-2019-17569
vendor_oracle·2020-07-15·CVSS 4.8
CVE-2019-17569 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Workload Manager (Apache Tomcat) — CVE-2019-17569
Oracle Oracle Database Server Risk Matrix: Workload Manager (Apache Tomcat) vulnerability
CVE: CVE-2019-17569
CVSS: 4.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Red Hat
tomcat: Regression in handling of Transfer-Encoding header allows for HTTP request smuggling
vendor_redhat·2020-02-24·CVSS 4.8
CVE-2019-17569 [MEDIUM] CWE-444 tomcat: Regression in handling of Transfer-Encoding header allows for HTTP request smuggling
tomcat: Regression in handling of Transfer-Encoding header allows for HTTP request smuggling
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
The refactoring in 9.0.28 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorr
Debian
CVE-2019-17569: tomcat9 - The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and ...
vendor_debian·2019·CVSS 4.8
CVE-2019-17569 [MEDIUM] CVE-2019-17569: tomcat9 - The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and ...
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Scope: local
bookworm: resolved (fixed in 9.0.31-1)
bullseye: resolved (fixed in 9.0.31-1)
forky: resolved (fixed in 9.0.31-1)
sid: resolved (fixed in 9.0.31-1)
trixie: resolved (fixed in 9.0.31-1)
Apache
Apache tomcat: CVE-2019-17569
vendor_apache·CVSS 4.8
CVE-2019-17569 [MEDIUM] Apache tomcat: CVE-2019-17569
Apache tomcat: CVE-2019-17569
The refactoring in 8.5.48 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely. This was fixed with commit 959f1dfd . This issue was reported to the Apache Tomcat Security Team by @ZeddYu on 12 December 2019. The issue was made public on 24 February 2020. Affects: 8.5.48 to 8.5.50 12 December 2019 Fixed in Apache Tomcat 8.5.50 Low: Session fixation
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.htmlhttps://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r88def002c5c78534674ca67472e035099fbe088813d50062094a1390%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/03/msg00006.htmlhttps://security.netapp.com/advisory/ntap-20200327-0005/https://www.debian.org/security/2020/dsa-4673https://www.debian.org/security/2020/dsa-4680https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.htmlhttps://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r88def002c5c78534674ca67472e035099fbe088813d50062094a1390%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/03/msg00006.htmlhttps://security.netapp.com/advisory/ntap-20200327-0005/https://www.debian.org/security/2020/dsa-4673https://www.debian.org/security/2020/dsa-4680https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2020-02-24
Published