CVE-2021-33037
published 2021-07-12CVE-2021-33037: Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some…
PriorityP350medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
75.35%
99.5th percentile
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | <= 9.0.46 | — |
| apache | tomcat | <= 10.0.6 | — |
| apache | tomcat | — | — |
| apache | tomcat | 8.5.0 – 8.5.66 | — |
| apache | tomee | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.43-2 (bookworm) | tomcat9 9.0.43-2 (bookworm) |
| mcafee | epolicy_orchestrator | < 5.10.0 | 5.10.0 |
| mcafee | epolicy_orchestrator | — | — |
| oracle | agile_plm | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_cloud_native_core_service_communication_proxy | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0.0 – 8.5.0.2 | — |
| oracle | communications_instant_messaging_server | — | — |
| oracle | communications_policy_management | — | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | communications_session_report_manager | 8.0.0 – 8.2.4.0 | — |
| oracle | communications_session_route_manager | 8.0.0 – 8.2.4 | — |
| oracle | graph_server_and_client | < 21.4 | 21.4 |
| oracle | healthcare_translational_research | — | — |
| oracle | hospitality_cruise_shipboard_property_management_system | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Qualys WAS QID 150367 detects CVE-2021-33037 by sending a version-probing HTTP/1.0 GET request and inspecting the Apache Tomcat version in the response banner. ↗
- →Flag HTTP requests where a client declares it will only accept an HTTP/1.0 response but includes a Transfer-Encoding header — Tomcat incorrectly ignored the transfer-encoding header in this scenario, enabling smuggling. ↗
- →Detect use of the 'identity' transfer-encoding value in requests forwarded through a reverse proxy to Tomcat, as Tomcat honoured this non-standard encoding. ↗
- →Alert on HTTP requests where chunked encoding is present but is not the final Transfer-Encoding value, as Tomcat failed to enforce this requirement, enabling request smuggling. ↗
- ·The vulnerability is only exploitable when Apache Tomcat is deployed behind a reverse proxy; standalone deployments have significantly reduced risk. ↗
- ·Affected versions are Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46, and 8.5.0 to 8.5.66; upgrade to 10.0.7, 9.0.48, or 8.5.68 respectively to remediate. ↗
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_apache5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: MFT Runtime Server (Apache Tomcat) — CVE-2021-33037
vendor_oracle·2022-04-15·CVSS 5.3
CVE-2021-33037 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: MFT Runtime Server (Apache Tomcat) — CVE-2021-33037
Oracle Oracle Fusion Middleware Risk Matrix: MFT Runtime Server (Apache Tomcat) vulnerability
CVE: CVE-2021-33037
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2022-03-31·CVSS 4.3
CVE-2021-33037 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly performed input verification.
A remote attacker could possibly use this issue to intercept sensitive
information. (CVE-2020-13943, CVE-2020-17527, CVE-2021-25122, CVE-2021-30640)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-33037)
It was discovered that Tomcat did not properly validate the input length. An
attacker could possibly use this to trigger an infinite loop, resulting in a
denial of service. (CVE-2021-25329, CVE-2021-41079)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Graph Server and Client Risk Matrix: Packaging/Install (Apache Tomcat) — CVE-2021-33037
vendor_oracle·2022-01-15·CVSS 5.3
CVE-2021-33037 [MEDIUM] Oracle Oracle Graph Server and Client Risk Matrix: Packaging/Install (Apache Tomcat) — CVE-2021-33037
Oracle Oracle Graph Server and Client Risk Matrix: Packaging/Install (Apache Tomcat) vulnerability
CVE: CVE-2021-33037
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Pricing (Apache Tomcat) — CVE-2021-33037
vendor_oracle·2021-10-15·CVSS 5.3
CVE-2021-33037 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Pricing (Apache Tomcat) — CVE-2021-33037
Oracle Oracle Communications Applications Risk Matrix: Pricing (Apache Tomcat) vulnerability
CVE: CVE-2021-33037
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Red Hat
tomcat: HTTP request smuggling when used with a reverse proxy
vendor_redhat·2021-07-12·CVSS 5.3
CVE-2021-33037 [MEDIUM] CWE-444 tomcat: HTTP request smuggling when used with a reverse proxy
tomcat: HTTP request smuggling when used with a reverse proxy
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
Statement: Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of OpenStack Platform 14 and is only receiving security fixes for Critical flaws.
Package: tomcat (Red Hat
Debian
CVE-2021-33037: tomcat9 - Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did no...
vendor_debian·2021·CVSS 5.3
CVE-2021-33037 [MEDIUM] CVE-2021-33037: tomcat9 - Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did no...
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
Scope: local
bookworm: resolved (fixed in 9.0.43-2)
bullseye: resolved (fixed in 9.0.43-2~deb11u1)
forky: resolved (fixed in 9.0.43-2)
sid: resolved (fixed in 9.0.43-2)
trixie: resolved (fixed in 9.0.43-2)
Apache
Apache tomcat: CVE-2021-33037
vendor_apache·CVSS 5.3
CVE-2021-33037 [MEDIUM] Apache tomcat: CVE-2021-33037
Apache tomcat: CVE-2021-33037
Apache Tomcat did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility of request smuggling when used with a reverse proxy. Specifically: Tomcat incorrectly ignored the transfer-encoding header if the client declared it would only accept an HTTP/1.0 response; Tomcat honoured the identify encoding; and Tomcat did not ensure that, if present, the chunked encoding was the final encoding. This was fixed with commits 3202703e , da0e7cb0 and 8874fa02 . This issue was reported to the Apache Tomcat Security team by Bahruz Jabiyev, Steven Sprecher and Kaan Onarlioglu of NEU seclab on 7 May 2021. The issue was made public on 12 July 2021. This issue was identified and reported responsibly . Affects: 8.5.0 to 8.5.
OSV
tomcat9 vulnerabilities
osv·2022-03-31·CVSS 4.3
CVE-2020-13943 [MEDIUM] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that Tomcat incorrectly performed input verification.
A remote attacker could possibly use this issue to intercept sensitive
information. (CVE-2020-13943, CVE-2020-17527, CVE-2021-25122, CVE-2021-30640)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-33037)
It was discovered that Tomcat did not properly validate the input length. An
attacker could possibly use this to trigger an infinite loop, resulting in a
denial of service. (CVE-2021-25329, CVE-2021-41079)
GHSA
HTTP Request Smuggling in Apache Tomcat
ghsa·2021-08-13
CVE-2021-33037 [MEDIUM] CWE-444 HTTP Request Smuggling in Apache Tomcat
HTTP Request Smuggling in Apache Tomcat
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
OSV
HTTP Request Smuggling in Apache Tomcat
osv·2021-08-13
CVE-2021-33037 [MEDIUM] HTTP Request Smuggling in Apache Tomcat
HTTP Request Smuggling in Apache Tomcat
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
OSV
CVE-2021-33037: Apache Tomcat 10
osv·2021-07-12·CVSS 5.3
CVE-2021-33037 [MEDIUM] CVE-2021-33037: Apache Tomcat 10
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
No detection rules found.
No public exploits indexed.
Qualys
Apache Tomcat HTTP Request Smuggling Vulnerability (CVE-2021-33037) | Qualys
blogs_qualys·2021-10-27·CVSS 5.3
CVE-2021-33037 [MEDIUM] Apache Tomcat HTTP Request Smuggling Vulnerability (CVE-2021-33037) | Qualys
#### Table of Contents
- About CVE-2021-33037
- Detecting vulnerability with Qualys WAS
- Report
- Solution
- Vendor Reference
- CVE Details
- Contributor
A vulnerability (CVE-2021-33037) discovered this year in Apache Tomcat causes incorrect parsing of the HTTP transfer-encoding request header in some circumstances, leading to the possibility of HTTP Request Smuggling (HRS) when used with a reverse proxy. HTTP Request Smuggling (HRS) is a web application vulnerability that enables an attacker to craft a single request that hides a second request within the body of the first request.
Qualys Web Application Scanning has added a new QID that detects this vulnerability by sending a request to the target server to determine if it is exploitable. Once detected, the vulnerability can be remed
Qualys
Apache Tomcat HTTP Request Smuggling Vulnerability (CVE-2021-33037)
blogs_qualys·2021-10-27·CVSS 5.3
CVE-2021-33037 [MEDIUM] Apache Tomcat HTTP Request Smuggling Vulnerability (CVE-2021-33037)
## Table of Contents
About CVE-2021-33037
Detecting vulnerability with Qualys WAS
Report
Solution
Vendor Reference
CVE Details
Contributor
A vulnerability (CVE-2021-33037) discovered this year in Apache Tomcat causes incorrect parsing of the HTTP transfer-encoding request header in some circumstances, leading to the possibility of HTTP Request Smuggling (HRS) when used with a reverse proxy. HTTP Request Smuggling (HRS) is a web application vulnerability that enables an attacker to craft a single request that hides a second request within the body of the first request.
Qualys Web Application Scanning has added a new QID that detects this vulnerability by sending a request to the target server to determine if it is exploitable. Once detected, the vulnerability can be remediated by u
Huntress
Tomcat 9 Vulnerability: Analysis, Detection, Removal | Huntress
blogs_huntress·CVSS 8.1
[HIGH] Tomcat 9 Vulnerability: Analysis, Detection, Removal | Huntress
## Tomcat 9 Vulnerability
Published: 12/05/2025
Written by: Lizzie Danielson
## What is Tomcat 9 Vulnerability?
The Tomcat 9 vulnerability refers to a series of security flaws impacting the Apache Tomcat 9 software, primarily affecting its ability to properly manage configurations, remote code execution (RCE), and unauthorized access scenarios. It has been classified as a high-risk vulnerability in cases where improper input validation compromises server environments. These vulnerabilities can enable attackers to exploit unpatched systems, often through malicious input or authentication loopholes. Notable CVEs associated with this include CVE-2019-0232 and CVE-2021-33037.
## When was it discovered?
The vulnerabilities in Tomcat 9 were disclosed at various times, depending on the spec
arXiv
Forecasting the risk of software choices: A model to foretell security vulnerabilities from library dependencies and source code evolution
arxiv_fulltext·2024-11-17
Forecasting the risk of software choices: A model to foretell security vulnerabilities from library dependencies and source code evolution
Carlos E.\ Budde
0000-0001-8807-1548
[email protected]
Ranindya Paramitha
0000-0002-6682-4243
[email protected]
University of Trento
Trento
Italy
Fabio Massacci
0000-0002-1091-8486
University of Trento
Trento
Italy
Vre Universiteit
Amsterdam
The Netherlands
Budde, Paramitha, Massacci
## Abstract
Software security mainly studies vulnerability detection: is my code vulnerable today?
This hinders risk estimation, so new approaches are emerging to forecast the occurrence of future vulnerabilities.
While useful, these approaches are coarse-grained and hard to employ for project-specific technical decisions.
We introduce a model capable of vulnerability forecasting at library level.
Formalising source-code evolution in time together with library dependency, our model
Bugzilla
CVE-2021-33037 tomcat: HTTP request smuggling when used with a reverse proxy
bugzilla·2021-07-12·CVSS 5.3
CVE-2021-33037 [MEDIUM] CVE-2021-33037 tomcat: HTTP request smuggling when used with a reverse proxy
CVE-2021-33037 tomcat: HTTP request smuggling when used with a reverse proxy
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
Reference:
https://lists.apache.org/thread.html/r612a79269b0d5e5780c62dfd34286a8037232fec0bc6f1a7e60c9381%40%3Cannounce.tomcat.apache.org%3E
Discussion:
Created tomcat tracking bugs for this issue:
Affects:
https://kc.mcafee.com/corporate/index?page=content&id=SB10366https://lists.apache.org/thread.html/r290aee55b72811fd19e75ac80f6143716c079170c5671b96932ed44b%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r40f921575aee8d7d34e53182f862c45cbb8f3d898c9d4e865c2ec262%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r612a79269b0d5e5780c62dfd34286a8037232fec0bc6f1a7e60c9381%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rc6ef52453bb996a98cb45442871a1db56b7c349939e45d829bf9ae37%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rd0dfea39829bc0606c936a16f6fca338127c86c0a1083970b45ac8d2%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/re01e7e93154e8bdf78a11a23f9686427bd3d51fc6e12c508645567b7%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rf1b54fd3f52f998ca4829159a88cc4c23d6cef5c6447d00948e75c97%40%3Ccommits.tomee.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/08/msg00009.htmlhttps://security.gentoo.org/glsa/202208-34https://security.netapp.com/advisory/ntap-20210827-0007/https://www.debian.org/security/2021/dsa-4952https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://kc.mcafee.com/corporate/index?page=content&id=SB10366https://lists.apache.org/thread.html/r290aee55b72811fd19e75ac80f6143716c079170c5671b96932ed44b%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r40f921575aee8d7d34e53182f862c45cbb8f3d898c9d4e865c2ec262%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r612a79269b0d5e5780c62dfd34286a8037232fec0bc6f1a7e60c9381%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rc6ef52453bb996a98cb45442871a1db56b7c349939e45d829bf9ae37%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rd0dfea39829bc0606c936a16f6fca338127c86c0a1083970b45ac8d2%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/re01e7e93154e8bdf78a11a23f9686427bd3d51fc6e12c508645567b7%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rf1b54fd3f52f998ca4829159a88cc4c23d6cef5c6447d00948e75c97%40%3Ccommits.tomee.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/08/msg00009.htmlhttps://security.gentoo.org/glsa/202208-34https://security.netapp.com/advisory/ntap-20210827-0007/https://www.debian.org/security/2021/dsa-4952https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-07-12
Published