CVE-2019-17569

medium Apache
CVSS v3 Base Score
4.8
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
8.9%
Exploitation probability in 30 days
Top 5% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Confidentiality
Low
Integrity
Low
Availability
None
Published: February 24, 2020 (2387 days ago)
Last Modified: August 25, 2026
Vendor: Apache
Source: NVD

Description

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

CWE

CWE-444

Affected Products

apache tomcatapache tomeeopensuse leapnetapp data availability servicesnetapp oncommand system managerdebian debian linuxoracle agile engineering data managementoracle agile product lifecycle managementoracle communications instant messaging serveroracle health sciences empirica inspections

References