Inconsistent interpretation of HTTP requests in Apache Tomcat - CVE-2019-17569
Published: March 6, 2020 / Updated: April 23, 2020
Vulnerability identifier: #VU25806
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17569
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attack.
The vulnerability exists due to improper input validation when processing a Transfer-Encoding headers. A remote attacker can send a specially crafted HTTP request and perform HTTP request smuggling attack.Affected software
Apache Tomcat
Cloud Foundry UAA
Amazon Linux AMI
Oracle Solaris
Opensuse
tomcat8 (Debian package)
tomcat9 (Debian package)
CF Deployment
Oracle Database Server
Cloud Foundry UAA
Amazon Linux AMI
Oracle Solaris
Opensuse
tomcat8 (Debian package)
tomcat9 (Debian package)
CF Deployment
Oracle Database Server
How to mitigate CVE-2019-17569
Install updates from vendor's website.
Apache Tomcat - addressed in versions 7.0.100, 8.5.51, 9.0.31
tomcat8 (Debian package) - update to 8.5.54-0+deb9u1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u1
CF Deployment - update to 12.40.0
Cloud Foundry UAA - update to 74.16.0
tomcat8 (Debian package) - update to 8.5.54-0+deb9u1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u1
CF Deployment - update to 12.40.0
Cloud Foundry UAA - update to 74.16.0
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Tomcat
- Amazon Linux AMI update for tomcat8
- Amazon Linux AMI update for tomcat7
- OpenSUSE Linux update for tomcat
- Cloud Foundry UAA update for Apache Tomcat
- Oracle Solaris update for third party packages
- Debian update for tomcat8
- Debian update for tomcat9
- Multiple vulnerabilities in Oracle Database Server