MEDIUM · 4.8

CVE-2020-1935

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as val...

Vulnerability Description

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

CVSS Score

4.8

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
ApacheTomcat>= 7.0.0, <= 7.0.99
DebianDebian Linux8.0
CanonicalUbuntu Linux16.04
OpensuseLeap15.1
NetappData Availability Services-
NetappOncommand System Manager>= 3.0.0, <= 3.1.3
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Product Lifecycle Management9.3.3
OracleCommunications Element Manager8.1.1
OracleCommunications Instant Messaging Server10.0.1.4.0
OracleHealth Sciences Empirica Inspections1.0.1.2
OracleHealth Sciences Empirica Signal7.3.3
OracleHospitality Guest Access4.2.0
OracleHyperion Infrastructure Technology11.1.2.4
OracleInstantis Enterprisetrack>= 17.1, <= 17.3
OracleMysql Enterprise Monitor>= 4.0.0, <= 4.0.12
OracleRetail Order Broker15.0
OracleSiebel Ui Framework<= 20.5
OracleTransportation Management6.3.7
OracleWorkload Manager12.2.0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-1935?

CVE-2020-1935 is a vulnerability with a CVSS score of 4.8 (MEDIUM). In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as val...

How severe is CVE-2020-1935?

CVE-2020-1935 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-1935?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Debian Debian Linux, Canonical Ubuntu Linux, Opensuse Leap, Netapp Data Availability Services.