Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CVE-2021-33037

CVE information

Published

2 years ago

Last Modified

5 months ago

CVSSv2.0 Severity

Medium

CVSSv3.1 Severity

Medium

Impact Analysis

Description

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding..

CVSSv2.0 Score

Severity
Medium
Base Score
5/10
Exploit Score
10/10
Access Vector
Network
Access Complexity
Low
Authentication Required
None
Impact Score
2.9/10
Confidentiality Impact
None
Availability Impact
None
Integrity Impact
Partial

CVSSv3.1 Score

Severity
Medium
Base Score
5.3/10
Exploit Score
3.9/10
Access Vector
Network
Access Complexity
Low
Privileges Required
None
Impact Score
1.4/10
Confidentiality Impact
None
Availability Impact
None
Integrity Impact
Low
Scope
Unchanged
User Interaction
None

Products Affected

CPE Affected Vulnerable Excluding Edit
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
  Yes
8.5.0 -
cpe:2.3:a:apache:tomee:8.0.6:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:managed_file_transfer:12.2.1.3.0:*:*:*:*:*:
  Yes
- -
cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:
  Yes
- -
cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:
  Yes
- -
cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:
  Yes
- -
cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:communications_policy_management:12.5.0:*:*
  Yes
- -
cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:
  Yes
- -
cpe:2.3:a:oracle:secure_global_desktop:5.6:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:hospitality_cruise_shipboard_property_manag
  Yes
- -
cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0
  Yes
- -
cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:
  Yes
8.0.0 -
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:communications_session_report_manager:*:*:*
  Yes
8.0.0 -
cpe:2.3:a:oracle:sd-wan_edge:9.1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.2.2:*:*
  Yes
- -
cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.3.1:*:*
  Yes
- -
cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.1.1:*:*
  Yes
- -
cpe:2.3:a:oracle:communications_diameter_signaling_router:*:
  Yes
8.0.0.0 -
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.1
  Yes
- -
cpe:2.3:a:oracle:communications_cloud_native_core_service_co
  Yes
- -
cpe:2.3:a:oracle:communications_instant_messaging_server:10.
  Yes
- -
cpe:2.3:a:oracle:graph_server_and_client:*:*:*:*:*:*:*:*
  Yes
- 21.4
cpe:2.3:a:oracle:healthcare_translational_research:4.1.0:*:*
  Yes
- -
cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_1:*:*:*:
  Yes
- -
cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_2:*:*:*:
  Yes
- -
cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_3:*:*:*:
  Yes
- -
cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_4:*:*:*:
  Yes
- -
cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_5:*:*:*:
  Yes
- -
cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_6:*:*:*:
  Yes
- -
cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:-:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:mcafee:epolicy_orchestrator:*:*:*:*:*:*:*:*
  Yes
- 5.10.0
cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_7:*:*:*:
  Yes
- -
cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_8:*:*:*:
  Yes
- -
cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_9:*:*:*:
  Yes
- -
cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_10:*:*:*
  Yes
- -