CVE Vulnerabilities

CVE-2005-2090

Published: Jul 05, 2005 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a Transfer-Encoding: chunked header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka HTTP Request Smuggling.

Affected Software

Name Vendor Start Version End Version
Tomcat Apache 4.1.24 (including) 4.1.24 (including)
Tomcat Apache 5.0.19 (including) 5.0.19 (including)
Red Hat Certificate System 7.3 RedHat ant-0:1.6.5-1jpp_1rh *
Red Hat Certificate System 7.3 RedHat avalon-logkit-0:1.2-2jpp_4rh *
Red Hat Certificate System 7.3 RedHat axis-0:1.2.1-1jpp_3rh *
Red Hat Certificate System 7.3 RedHat classpathx-jaf-0:1.0-2jpp_6rh *
Red Hat Certificate System 7.3 RedHat classpathx-mail-0:1.1.1-2jpp_8rh *
Red Hat Certificate System 7.3 RedHat geronimo-specs-0:1.0-0.M4.1jpp_10rh *
Red Hat Certificate System 7.3 RedHat jakarta-commons-modeler-0:2.0-3jpp_2rh *
Red Hat Certificate System 7.3 RedHat log4j-0:1.2.12-1jpp_1rh *
Red Hat Certificate System 7.3 RedHat mx4j-1:3.0.1-1jpp_4rh *
Red Hat Certificate System 7.3 RedHat pcsc-lite-0:1.3.3-3.el4 *
Red Hat Certificate System 7.3 RedHat rhpki-ca-0:7.3.0-20.el4 *
Red Hat Certificate System 7.3 RedHat rhpki-java-tools-0:7.3.0-10.el4 *
Red Hat Certificate System 7.3 RedHat rhpki-kra-0:7.3.0-14.el4 *
Red Hat Certificate System 7.3 RedHat rhpki-manage-0:7.3.0-19.el4 *
Red Hat Certificate System 7.3 RedHat rhpki-native-tools-0:7.3.0-6.el4 *
Red Hat Certificate System 7.3 RedHat rhpki-ocsp-0:7.3.0-13.el4 *
Red Hat Certificate System 7.3 RedHat rhpki-tks-0:7.3.0-13.el4 *
Red Hat Certificate System 7.3 RedHat tomcat5-0:5.5.23-0jpp_4rh.16 *
Red Hat Certificate System 7.3 RedHat xerces-j2-0:2.7.1-1jpp_1rh *
Red Hat Certificate System 7.3 RedHat xml-commons-0:1.3.02-2jpp_1rh *
Red Hat Developer Suite V.3 RedHat jakarta-commons-modeler-0:2.0-3jpp_3rh *
Red Hat Developer Suite V.3 RedHat tomcat5-0:5.5.23-0jpp_6rh *
Red Hat Enterprise Linux 5 RedHat jakarta-commons-modeler-0:1.1-8jpp.1.0.2.el5 *
Red Hat Enterprise Linux 5 RedHat tomcat5-0:5.5.23-0jpp.1.0.3.el5 *
Red Hat Network Satellite Server v 4.0 RedHat jakarta-commons-pool-0:1.2-2jpp_2rh *
Red Hat Network Satellite Server v 4.0 RedHat tomcat5-0:5.0.30-0jpp_6rh *
Red Hat Network Satellite Server v 4.0 RedHat tyrex-0:1.0.1-2jpp_2rh *
Red Hat Network Satellite Server v 4.0 (RHEL3) RedHat jakarta-commons-pool-0:1.2-2jpp_2rh *
Red Hat Network Satellite Server v 4.0 (RHEL3) RedHat tomcat5-0:5.0.30-0jpp_6rh *
Red Hat Network Satellite Server v 4.0 (RHEL3) RedHat tyrex-0:1.0.1-2jpp_2rh *
Red Hat Network Satellite Server v 4.1 RedHat jakarta-commons-pool-0:1.2-2jpp_2rh *
Red Hat Network Satellite Server v 4.1 RedHat tomcat5-0:5.0.30-0jpp_6rh *
Red Hat Network Satellite Server v 4.1 RedHat tyrex-0:1.0.1-2jpp_2rh *
Red Hat Network Satellite Server v 4.1 (RHEL3) RedHat jakarta-commons-pool-0:1.2-2jpp_2rh *
Red Hat Network Satellite Server v 4.1 (RHEL3) RedHat tomcat5-0:5.0.30-0jpp_6rh *
Red Hat Network Satellite Server v 4.1 (RHEL3) RedHat tyrex-0:1.0.1-2jpp_2rh *
Red Hat Network Satellite Server v 4.2 RedHat jakarta-commons-pool-0:1.2-2jpp_2rh *
Red Hat Network Satellite Server v 4.2 RedHat tomcat5-0:5.0.30-0jpp_6rh *
Red Hat Network Satellite Server v 4.2 RedHat tyrex-0:1.0.1-2jpp_2rh *
Red Hat Network Satellite Server v 4.2 RedHat jabberd-0:2.0s10-3.38.rhn *
Red Hat Network Satellite Server v 4.2 RedHat java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4 *
Red Hat Network Satellite Server v 4.2 RedHat jfreechart-0:0.9.20-3.rhn *
Red Hat Network Satellite Server v 4.2 RedHat openmotif21-0:2.1.30-11.RHEL4.6 *
Red Hat Network Satellite Server v 4.2 RedHat perl-Crypt-CBC-0:2.24-1.el4 *
Red Hat Network Satellite Server v 4.2 RedHat rhn-apache-0:1.3.27-36.rhn.rhel4 *
Red Hat Network Satellite Server v 4.2 RedHat rhn-modjk-0:1.2.23-2rhn.rhel4 *
Red Hat Network Satellite Server v 4.2 RedHat rhn-modperl-0:1.29-16.rhel4 *
Red Hat Network Satellite Server v 4.2 RedHat rhn-modssl-0:2.8.12-8.rhn.10.rhel4 *
Red Hat Network Satellite Server v 4.2 RedHat tomcat5-0:5.0.30-0jpp_10rh *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat jakarta-commons-pool-0:1.2-2jpp_2rh *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat tomcat5-0:5.0.30-0jpp_6rh *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat tyrex-0:1.0.1-2jpp_2rh *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat jabberd-0:2.0s10-3.37.rhn *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3 *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat jfreechart-0:0.9.20-3.rhn *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat openmotif21-0:2.1.30-9.RHEL3.8 *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat perl-Crypt-CBC-0:2.24-1.el3 *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat rhn-apache-0:1.3.27-36.rhn.rhel3 *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat rhn-modjk-0:1.2.23-2rhn.rhel3 *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat rhn-modperl-0:1.29-16.rhel3 *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat rhn-modssl-0:2.8.12-8.rhn.10.rhel3 *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat tomcat5-0:5.0.30-0jpp_10rh *
Red Hat Network Satellite Server v 5.0 RedHat jakarta-commons-pool-0:1.2-2jpp_2rh *
Red Hat Network Satellite Server v 5.0 RedHat tomcat5-0:5.0.30-0jpp_6rh *
Red Hat Network Satellite Server v 5.0 RedHat tyrex-0:1.0.1-2jpp_2rh *
Red Hat Network Satellite Server v 5.0 RedHat jabberd-0:2.0s10-3.38.rhn *
Red Hat Network Satellite Server v 5.0 RedHat java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4 *
Red Hat Network Satellite Server v 5.0 RedHat jfreechart-0:0.9.20-3.rhn *
Red Hat Network Satellite Server v 5.0 RedHat openmotif21-0:2.1.30-11.RHEL4.6 *
Red Hat Network Satellite Server v 5.0 RedHat perl-Crypt-CBC-0:2.24-1.el4 *
Red Hat Network Satellite Server v 5.0 RedHat rhn-apache-0:1.3.27-36.rhn.rhel4 *
Red Hat Network Satellite Server v 5.0 RedHat rhn-modjk-0:1.2.23-2rhn.rhel4 *
Red Hat Network Satellite Server v 5.0 RedHat rhn-modperl-0:1.29-16.rhel4 *
Red Hat Network Satellite Server v 5.0 RedHat rhn-modssl-0:2.8.12-8.rhn.10.rhel4 *
Red Hat Network Satellite Server v 5.0 RedHat tomcat5-0:5.0.30-0jpp_10rh *
Red Hat Web Application Stack for RHEL 4 RedHat jbossas-0:4.0.5-2.CP04.el4s1.2 *
RHAPS Version 1 for RHEL 3 RedHat tomcat5-0:5.0.30-0jpp_5rh *
RHAPS Version 2 for RHEL 4 RedHat jakarta-commons-modeler-0:2.0-3jpp_2rh *
RHAPS Version 2 for RHEL 4 RedHat tomcat5-0:5.5.23-0jpp_4rh.3 *

References