CVE-2019-17569 Details
Description
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | >= 7.0.98, <= 7.0.99 >= 8.5.48, <= 8.5.50 >= 9.0.28, <= 9.0.30 |
CPE
Remediation
| |
| apache tomee | 7.0.7 |
CPE
Remediation
| |
| opensuse leap | 15.1 |
CPE
Remediation
| |
| netapp data availability services | All versions |
CPE
Remediation
| |
| netapp oncommand system manager | >= 3.0.0, <= 3.1.3 |
CPE
Remediation
| |
| debian debian linux | 9.0 10.0 |
CPE
Remediation
| |
| oracle agile engineering data management | 6.2.1.0 |
CPE
Remediation
| |
| oracle agile product lifecycle management | 9.3.3 9.3.5 9.3.6 |
CPE
Remediation
| |
| oracle communications instant messaging server | 10.0.1.4.0 |
CPE
Remediation
| |
| oracle health sciences empirica inspections | 1.0.1.2 |
CPE
Remediation
| |
| oracle health sciences empirica signal | 7.3.3 |
CPE
Remediation
| |
| oracle hospitality guest access | 4.2.0 4.2.1 |
CPE
Remediation
| |
| oracle instantis enterprisetrack | >= 17.1, <= 17.3 |
CPE
Remediation
| |
| oracle mysql enterprise monitor | <= 4.0.12 >= 8.0.0, <= 8.0.20 |
CPE
Remediation
| |
| oracle transportation management | 6.3.7 |
CPE
Remediation
| |
| oracle workload manager | 12.2.0.1 18c 19c |
CPE
Remediation
| |
Change History
19 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 25, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 25, 2026 | CPE Deprecation Remap | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Sep 2, 2022 | Modified Analysis | [email protected] |
| Jan 20, 2021 | CVE Modified | [email protected] |
| Oct 20, 2020 | CVE Modified | [email protected] |
| Jul 15, 2020 | CVE Modified | [email protected] |
| May 7, 2020 | CVE Modified | [email protected] |
| May 4, 2020 | CVE Modified | [email protected] |
| Mar 27, 2020 | CVE Modified | [email protected] |
| Mar 23, 2020 | CVE Modified | [email protected] |
| Mar 20, 2020 | CVE Modified | [email protected] |
| Mar 15, 2020 | CVE Modified | [email protected] |
| Mar 5, 2020 | Initial Analysis | [email protected] |
| Mar 4, 2020 | CVE Modified | [email protected] |