CVE Database
/

CVE-2013-4286

Back to search

CVE-2013-4286

Published: Feb 26, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identification of a request's length and conduct request-smuggling attacks via (1) multiple Content-Length headers or (2) a Content-Length header and a "Transfer-Encoding: chunked" header. NOTE: this vulnerability exists because of an incomplete fix for CVE-2005-2090.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2014:0345
vendor-advisory
x_refsource_REDHAT
59733
third-party-advisory
x_refsource_SECUNIA
RHSA-2014:0686
vendor-advisory
x_refsource_REDHAT
MDVSA-2015:052
vendor-advisory
x_refsource_MANDRIVA
59724
third-party-advisory
x_refsource_SECUNIA
DSA-3530
vendor-advisory
x_refsource_DEBIAN
57675
third-party-advisory
x_refsource_SECUNIA
RHSA-2014:0344
vendor-advisory
x_refsource_REDHAT
HPSBUX03150
vendor-advisory
x_refsource_HP
59722
third-party-advisory
x_refsource_SECUNIA
59675
third-party-advisory
x_refsource_SECUNIA
USN-2130-1
vendor-advisory
x_refsource_UBUNTU
59873
third-party-advisory
x_refsource_SECUNIA
RHSA-2014:0343
vendor-advisory
x_refsource_REDHAT
HPSBOV03503
vendor-advisory
x_refsource_HP
65773
vdb-entry
x_refsource_BID
59036
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now