7.5
CVSSv3

CVE-2023-46589

Published: 28/11/2023 Updated: 05/01/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 up to and including 11.0.0-M10, from 10.1.0-M1 up to and including 10.1.15, from 9.0.0-M1 up to and including 9.0.82 and from 8.5.0 up to and including 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomcat 11.0.0

apache tomcat

Vendor Advisories

Debian Bug report logs - #1057082 tomcat10: CVE-2023-46589 Package: src:tomcat10; Maintainer for src:tomcat10 is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 29 Nov 2023 12:12:01 UTC Severity: important Tags: fixed-upstream, s ...
概要 Important: tomcat security update タイプ/重大度 Security Advisory: Important Red Hat Insights パッチ分析 このアドバイザリーの影響を受けるシステムを特定し、修正します。 影響を受けるシステムの表示 トピック An update for tomcat is now available for Red Hat Enterprise Lin ...
Synopsis Important: tomcat security update Type / Sévérité Security Advisory: Important Analyse des correctifs dans Red Hat Insights Identifiez et remédiez aux systèmes concernés par cette alerte Voir les systèmes concernés Sujet An update for tomcat is now available for Red Hat Enterprise Linux 8Red Hat Product Security h ...
Improper Input Validation vulnerability in Apache TomcatTomcat from 1100-M1 through 1100-M10, from 1010-M1 through 10115, from 900-M1 through 9082 and from 850 through 8595 did not correctly parse HTTP trailer headers A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requ ...
Improper Input Validation vulnerability in Apache TomcatTomcat from 1100-M1 through 1100-M10, from 1010-M1 through 10115, from 900-M1 through 9082 and from 850 through 8595 did not correctly parse HTTP trailer headers A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requ ...
Hitachi Ops Center Administrator contains the following vulnerabilities: CVE-2023-45648, CVE-2023-46589, CVE-2023-46604 Affected products and versions are listed below Please upgrade your version to the appropriate version ...