SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-17569

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression.

MEDIUM 4.8EPSS 8.87%

Does this matter?

Lower severity and a low EPSS score (8.87%). Track it; it rarely justifies an emergency change on its own.

Description

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

CVSS 3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
8.87% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-444
Affected
apache/tomcat · apache/tomee · opensuse/leap · netapp/data availability services · netapp/oncommand system manager · debian/debian linux · oracle/agile engineering data management · oracle/agile product lifecycle management · oracle/communications instant messaging server · oracle/health sciences empirica inspections · oracle/health sciences empirica signal · oracle/hospitality guest access · oracle/instantis enterprisetrack · oracle/mysql enterprise monitor · oracle/transportation management · oracle/workload manager
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.