CVE-2019-17569: Apache Tomcat
Medium severity, CVSS 4.8. EPSS: 8.9% chance of exploitation in the next 30 days.
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Affected products
- Apache Tomcat: from 7.0.98, up to and including 7.0.99; from 8.5.48, up to and including 8.5.50; from 9.0.28, up to and including 9.0.30
- Apache Tomee: version 7.0.7 only
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Netapp Data Availability Services: affected versions not specified
- Netapp Oncommand System Manager: from 3.0.0, up to and including 3.1.3
- Opensuse Leap: version 15.1 only
- Oracle Agile Engineering Data Management: version 6.2.1.0 only
- Oracle Agile Product Lifecycle Management: version 9.3.3 only; version 9.3.5 only; version 9.3.6 only
- Oracle Communications Instant Messaging Server: version 10.0.1.4.0 only
- Oracle Health Sciences Empirica Inspections: version 1.0.1.2 only
- Oracle Health Sciences Empirica Signal: version 7.3.3 only
- Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
- Oracle Instantis Enterprisetrack: from 17.1, up to and including 17.3
- Oracle MySQL Enterprise Monitor: up to and including 4.0.12; from 8.0.0, up to and including 8.0.20
- Oracle Transportation Management: version 6.3.7 only
- Oracle Workload Manager: version 12.2.0.1 only; version 18c only; version 19c only
Published 2020-02-24. Last modified 2026-08-25.