CVE-2021-33037Medium· 5.3▾ SunlitApache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse pr…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 15.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
75%
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
tomcat >= 8.5.0, <= 8.5.66tomcat > 9.0.0, <= 9.0.46tomcat > 10.0.0, <= 10.0.6tomee = 8.0.6debian_linux = 9.0debian_linux = 10.0agile_product_lifecycle_management = 9.3.6communications_cloud_native_core_policy = 1.14.0communications_cloud_native_core_service_communication_proxy = 1.14.0communications_diameter_signaling_router >= 8.0.0.0, <= 8.5.0.2communications_instant_messaging_server = 10.0.1.5.0communications_policy_management = 12.5.0communications_pricing_design_center = 12.0.0.3.0communications_session_report_manager >= 8.0.0, <= 8.2.4.0communications_session_route_manager >= 8.0.0, <= 8.2.4graph_server_and_client < 21.4healthcare_translational_research = 4.1.0hospitality_cruise_shipboard_property_management_system = 20.1.0instantis_enterprisetrack = 17.1instantis_enterprisetrack = 17.2instantis_enterprisetrack = 17.3managed_file_transfer = 12.2.1.3.0managed_file_transfer = 12.2.1.4.0mysql_enterprise_monitor <= 8.0.25sd-wan_edge = 9.0sd-wan_edge = 9.1secure_global_desktop = 5.6utilities_testing_accelerator = 6.0.0.1.1utilities_testing_accelerator = 6.0.0.2.2utilities_testing_accelerator = 6.0.0.3.1epolicy_orchestrator < 5.10.0epolicy_orchestrator = 5.10.0Upgrade past the affected range:
graph_server_and_client 21.4epolicy_orchestrator 5.10.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-25329High· 7.0The fix for CVE-2020-9484 was incomplete
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…
CVE-2020-13935High· 7.5The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104
CVE-2020-13934High· 7.5An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2
CVE-2020-9484High· 7.0When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…
CVE-2021-24122Medium· 5.9When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some con…