cbcvebase.
CVE-2021-33037
published 2021-07-12

CVE-2021-33037: Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
apachetomcat<= 9.0.46
apachetomcat<= 10.0.6
apachetomcat
apachetomcat8.5.0 – 8.5.66
apachetomee
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
debiandebian_linux
debiandebian_linux
debiantomcat9< tomcat9 9.0.43-2 (bookworm)tomcat9 9.0.43-2 (bookworm)
mcafeeepolicy_orchestrator< 5.10.05.10.0
mcafeeepolicy_orchestrator
oracleagile_plm
oraclecommunications_cloud_native_core_policy
oraclecommunications_cloud_native_core_service_communication_proxy
oraclecommunications_diameter_signaling_router8.0.0.0 – 8.5.0.2
oraclecommunications_instant_messaging_server
oraclecommunications_policy_management
oraclecommunications_pricing_design_center
oraclecommunications_session_report_manager8.0.0 – 8.2.4.0
oraclecommunications_session_route_manager8.0.0 – 8.2.4
oraclegraph_server_and_client< 21.421.4
oraclehealthcare_translational_research
oraclehospitality_cruise_shipboard_property_management_system

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM