CVE-2020-1935Medium· 4.8▾ SunlitIn Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 26.4 · likelihood 1.9 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
9.4%
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
tomcat >= 7.0.0, <= 7.0.99tomcat >= 8.5.0, <= 8.5.50tomcat >= 9.0.0, <= 9.0.30tomcat = 9.0.0debian_linux = 8.0debian_linux = 9.0debian_linux = 10.0ubuntu_linux = 16.04leap = 15.1data_availability_servicesoncommand_system_manager >= 3.0.0, <= 3.1.3agile_engineering_data_management = 6.2.1.0agile_product_lifecycle_management = 9.3.3agile_product_lifecycle_management = 9.3.5agile_product_lifecycle_management = 9.3.6communications_element_manager = 8.1.1communications_element_manager = 8.2.0communications_element_manager = 8.2.1communications_instant_messaging_server = 10.0.1.4.0health_sciences_empirica_inspections = 1.0.1.2health_sciences_empirica_signal = 7.3.3hospitality_guest_access = 4.2.0hospitality_guest_access = 4.2.1hyperion_infrastructure_technology = 11.1.2.4instantis_enterprisetrack >= 17.1, <= 17.3mysql_enterprise_monitor >= 4.0.0, <= 4.0.12mysql_enterprise_monitor >= 8.0.0, <= 8.0.20retail_order_broker = 15.0siebel_ui_framework <= 20.5transportation_management = 6.3.7workload_manager = 12.2.0.1workload_manager = 18cworkload_manager = 19cRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2019-17569Medium· 4.8The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression
CVE-2020-11996High· 7.5A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds
CVE-2019-17563High· 7.5When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack
CVE-2020-13935High· 7.5The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104
CVE-2020-13934High· 7.5An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2
CVE-2020-9484High· 7.0When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…