{"id":"CVE-2019-17569","title":"The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression","summary":"The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a pos…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-444"],"vendor":"apache","product":"tomcat","affected":["tomcat >= 7.0.98, <= 7.0.99","tomcat >= 8.5.48, <= 8.5.50","tomcat >= 9.0.28, <= 9.0.30","tomee = 7.0.7","leap = 15.1","data_availability_services","oncommand_system_manager >= 3.0.0, <= 3.1.3","debian_linux = 9.0","debian_linux = 10.0","agile_engineering_data_management = 6.2.1.0","agile_product_lifecycle_management = 9.3.3","agile_product_lifecycle_management = 9.3.5","agile_product_lifecycle_management = 9.3.6","communications_instant_messaging_server = 10.0.1.4.0","health_sciences_empirica_inspections = 1.0.1.2","health_sciences_empirica_signal = 7.3.3","hospitality_guest_access = 4.2.0","hospitality_guest_access = 4.2.1","instantis_enterprisetrack >= 17.1, <= 17.3","mysql_enterprise_monitor <= 4.0.12","mysql_enterprise_monitor >= 8.0.0, <= 8.0.20","transportation_management = 6.3.7","workload_manager = 12.2.0.1","workload_manager = 18c","workload_manager = 19c"],"published":"2020-02-24","updated":"2026-08-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-17569","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r88def002c5c78534674ca67472e035099fbe088813d50062094a1390%40%3Cannounce.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20200327-0005/","label":"security@apache.org"},{"url":"https://www.debian.org/security/2020/dsa-4673","label":"security@apache.org"},{"url":"https://www.debian.org/security/2020/dsa-4680","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"security@apache.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r88def002c5c78534674ca67472e035099fbe088813d50062094a1390%40%3Cannounce.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20200327-0005/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2020/dsa-4673","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2020/dsa-4680","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.08872,"epssPercentile":0.9504,"ingestedAt":"2026-08-25T17:29:29.280Z","slug":"CVE-2019-17569","body":"## Overview\n\nThe refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.\n\n## Affected\n\n- `tomcat >= 7.0.98, <= 7.0.99`\n- `tomcat >= 8.5.48, <= 8.5.50`\n- `tomcat >= 9.0.28, <= 9.0.30`\n- `tomee = 7.0.7`\n- `leap = 15.1`\n- `data_availability_services`\n- `oncommand_system_manager >= 3.0.0, <= 3.1.3`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `agile_engineering_data_management = 6.2.1.0`\n- `agile_product_lifecycle_management = 9.3.3`\n- `agile_product_lifecycle_management = 9.3.5`\n- `agile_product_lifecycle_management = 9.3.6`\n- `communications_instant_messaging_server = 10.0.1.4.0`\n- `health_sciences_empirica_inspections = 1.0.1.2`\n- `health_sciences_empirica_signal = 7.3.3`\n- `hospitality_guest_access = 4.2.0`\n- `hospitality_guest_access = 4.2.1`\n- `instantis_enterprisetrack >= 17.1, <= 17.3`\n- `mysql_enterprise_monitor <= 4.0.12`\n- `mysql_enterprise_monitor >= 8.0.0, <= 8.0.20`\n- `transportation_management = 6.3.7`\n- `workload_manager = 12.2.0.1`\n- `workload_manager = 18c`\n- `workload_manager = 19c`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":26.4,"likelihood":1.8,"exploitation":0,"ransomware":0},"changes":[]}