Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
{
"unresolved_ranges": [
{
"vendor_product": "mcafee:epolicy_orchestrator",
"extracted_events": [
{
"fixed": "5.10.0"
}
],
"cpes": [
"cpe:2.3:a:mcafee:epolicy_orchestrator:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"vendor_product": "oracle:communications_diameter_signaling_router",
"extracted_events": [
{
"introduced": "8.0.0.0"
},
{
"last_affected": "8.5.0.2"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"vendor_product": "oracle:communications_session_report_manager",
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.2.4.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"vendor_product": "oracle:communications_session_route_manager",
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.2.4"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"vendor_product": "oracle:graph_server_and_client",
"extracted_events": [
{
"fixed": "21.4"
}
],
"cpes": [
"cpe:2.3:a:oracle:graph_server_and_client:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"vendor_product": "oracle:mysql_enterprise_monitor",
"extracted_events": [
{
"last_affected": "8.0.25"
}
],
"cpes": [
"cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"vendor_product": "debian:debian_linux",
"extracted_events": [
{
"last_affected": "9.0"
},
{
"last_affected": "10.0"
}
],
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "mcafee:epolicy_orchestrator",
"extracted_events": [
{
"last_affected": "5.10.0-NA"
},
{
"last_affected": "5.10.0-update_1"
},
{
"last_affected": "5.10.0-update_10"
},
{
"last_affected": "5.10.0-update_2"
},
{
"last_affected": "5.10.0-update_3"
},
{
"last_affected": "5.10.0-update_4"
},
{
"last_affected": "5.10.0-update_5"
},
{
"last_affected": "5.10.0-update_6"
},
{
"last_affected": "5.10.0-update_7"
},
{
"last_affected": "5.10.0-update_8"
},
{
"last_affected": "5.10.0-update_9"
}
],
"cpes": [
"cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:-:*:*:*:*:*:*",
"cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_10:*:*:*:*:*:*",
"cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_1:*:*:*:*:*:*",
"cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_2:*:*:*:*:*:*",
"cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_3:*:*:*:*:*:*",
"cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_4:*:*:*:*:*:*",
"cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_5:*:*:*:*:*:*",
"cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_6:*:*:*:*:*:*",
"cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_7:*:*:*:*:*:*",
"cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_8:*:*:*:*:*:*",
"cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_9:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:agile_plm",
"extracted_events": [
{
"last_affected": "9.3.6"
}
],
"cpes": [
"cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:communications_cloud_native_core_policy",
"extracted_events": [
{
"last_affected": "1.14.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:communications_cloud_native_core_service_communication_proxy",
"extracted_events": [
{
"last_affected": "1.14.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.14.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:communications_instant_messaging_server",
"extracted_events": [
{
"last_affected": "10.0.1.5.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.5.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:communications_policy_management",
"extracted_events": [
{
"last_affected": "12.5.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_policy_management:12.5.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:communications_pricing_design_center",
"extracted_events": [
{
"last_affected": "12.0.0.3.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.3.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:healthcare_translational_research",
"extracted_events": [
{
"last_affected": "4.1.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:healthcare_translational_research:4.1.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:hospitality_cruise_shipboard_property_management_system",
"extracted_events": [
{
"last_affected": "20.1.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:hospitality_cruise_shipboard_property_management_system:20.1.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:instantis_enterprisetrack",
"extracted_events": [
{
"last_affected": "17.1"
},
{
"last_affected": "17.2"
},
{
"last_affected": "17.3"
}
],
"cpes": [
"cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:managed_file_transfer",
"extracted_events": [
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:managed_file_transfer:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:sd-wan_edge",
"extracted_events": [
{
"last_affected": "9.0"
},
{
"last_affected": "9.1"
}
],
"cpes": [
"cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:sd-wan_edge:9.1:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:secure_global_desktop",
"extracted_events": [
{
"last_affected": "5.6"
}
],
"cpes": [
"cpe:2.3:a:oracle:secure_global_desktop:5.6:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "oracle:utilities_testing_accelerator",
"extracted_events": [
{
"last_affected": "6.0.0.1.1"
},
{
"last_affected": "6.0.0.2.2"
},
{
"last_affected": "6.0.0.3.1"
}
],
"cpes": [
"cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.1.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.2.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.3.1:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
}
]
}{
"extracted_events": [
{
"introduced": "8.5.0"
},
{
"last_affected": "8.5.66"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.46"
},
{
"last_affected": "10.0.6"
}
],
"cpe": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.6"
}
],
"cpe": "cpe:2.3:a:apache:tomee:8.0.6:*:*:*:*:*:*:*",
"source": "CPE_STRING"
}