Lucene search

K
cve[email protected]CVE-2005-2090
HistoryJul 05, 2005 - 4:00 a.m.

CVE-2005-2090

2005-07-0504:00:00
web.nvd.nist.gov
106
cve
2005-2090
http request smuggling
jakarta tomcat
coyote/1.1
coyote/1.0
xss
web cache poisoning
web application firewall
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

3.6 Low

AI Score

Confidence

High

0.972 High

EPSS

Percentile

99.8%

Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a “Transfer-Encoding: chunked” header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka “HTTP Request Smuggling.”

Affected configurations

NVD
Node
apachetomcatMatch4.1.24
OR
apachetomcatMatch5.0.19

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

3.6 Low

AI Score

Confidence

High

0.972 High

EPSS

Percentile

99.8%