MEDIUM · 4.8

CVE-2019-17569

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were i...

Vulnerability Description

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

CVSS Score

4.8

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
ApacheTomcat>= 7.0.98, <= 7.0.99
ApacheTomee7.0.7
OpensuseLeap15.1
NetappData Availability Services-
NetappOncommand System Manager>= 3.0.0, <= 3.1.3
DebianDebian Linux9.0
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Plm9.3.3
OracleCommunications Instant Messaging Server10.0.1.4.0
OracleHealth Sciences Empirica Inspections1.0.1.2
OracleHealth Sciences Empirica Signal7.3.3
OracleHospitality Guest Access4.2.0
OracleInstantis Enterprisetrack>= 17.1, <= 17.3
OracleMysql Enterprise Monitor<= 4.0.12
OracleTransportation Management6.3.7
OracleWorkload Manager12.2.0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-17569?

CVE-2019-17569 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were i...

How severe is CVE-2019-17569?

CVE-2019-17569 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-17569?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Apache Tomee, Opensuse Leap, Netapp Data Availability Services, Netapp Oncommand System Manager.