Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7774
HistoryNov 13, 2018 - 6:55 a.m.

HTTP Request Smuggling

2018-11-1306:55:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20

EPSS

0.972

Percentile

99.8%

Apache Tomcat is vulnerable to HTTP request smuggling. Incorrect handling of HTTP requests allows a remote attacker to poison the web cache, bypass web application firewall protections or perform XSS attacks. The vulnerability is exploited by submitting crafted values for the Transfer-Encoding and Content-Length HTTP headers.

References