← All CVEs

CVE-2021-33037

medium · 5.3

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.

5.3
CVSS
75.4%
EPSS (exploit prob.)
99th
EPSS percentile
2021-07-12
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses

CWE-444

Affected products

VendorProductAffected versions
apachetomcat>= 8.5.0, <= 8.5.66
apachetomcat> 9.0.0, <= 9.0.46
apachetomcat> 10.0.0, <= 10.0.6
apachetomee8.0.6
debiandebian_linux9.0
debiandebian_linux10.0
oracleagile_product_lifecycle_management9.3.6
oraclecommunications_cloud_native_core_policy1.14.0
oraclecommunications_cloud_native_core_service_communication_proxy1.14.0
oraclecommunications_diameter_signaling_router>= 8.0.0.0, <= 8.5.0.2
oraclecommunications_instant_messaging_server10.0.1.5.0
oraclecommunications_policy_management12.5.0
oraclecommunications_pricing_design_center12.0.0.3.0
oraclecommunications_session_report_manager>= 8.0.0, <= 8.2.4.0
oraclecommunications_session_route_manager>= 8.0.0, <= 8.2.4
oraclegraph_server_and_client< 21.4
oraclehealthcare_translational_research4.1.0
oraclehospitality_cruise_shipboard_property_management_system20.1.0
oracleinstantis_enterprisetrack17.1
oracleinstantis_enterprisetrack17.2
oracleinstantis_enterprisetrack17.3
oraclemanaged_file_transfer12.2.1.3.0
oraclemanaged_file_transfer12.2.1.4.0
oraclemysql_enterprise_monitor<= 8.0.25
oraclesd-wan_edge9.0
oraclesd-wan_edge9.1
oraclesecure_global_desktop5.6
oracleutilities_testing_accelerator6.0.0.1.1
oracleutilities_testing_accelerator6.0.0.2.2
oracleutilities_testing_accelerator6.0.0.3.1
mcafeeepolicy_orchestrator< 5.10.0
mcafeeepolicy_orchestrator5.10.0
mcafeeepolicy_orchestrator5.10.0
mcafeeepolicy_orchestrator5.10.0
mcafeeepolicy_orchestrator5.10.0
mcafeeepolicy_orchestrator5.10.0
mcafeeepolicy_orchestrator5.10.0
mcafeeepolicy_orchestrator5.10.0
mcafeeepolicy_orchestrator5.10.0
mcafeeepolicy_orchestrator5.10.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-33037