CVE-2013-4286

Impact:
Moderate
Public Date:
2014-02-25
IAVA:
2015-B-0083
Bugzilla:
1069921: CVE-2013-4286 tomcat: multiple content-length header poisoning flaws
It was found that when Tomcat / JBoss Web processed a series of HTTP requests in which at least one request contained either multiple content-length headers, or one content-length header with a chunked transfer-encoding header, Tomcat / JBoss Web would incorrectly handle the request. A remote attacker could use this flaw to poison a web cache, perform cross-site scripting (XSS) attacks, or obtain sensitive information from other requests.

Find out more about CVE-2013-4286 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 5.8
Base Metrics AV:N/AC:M/Au:N/C:P/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 Server (tomcat7) RHSA-2014:0526 2014-05-21
Red Hat JBoss Portal 6.2 RHSA-2015:1009 2015-05-14
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 Server (tomcat6) RHSA-2014:0525 2014-05-21
Red Hat JBoss Fuse Service Works 6.0 RHSA-2014:0459 2014-04-30
Red Hat JBoss Web Server 2.0 RHSA-2014:0527 2014-05-21
Red Hat Enterprise Linux 6 (tomcat6) RHSA-2014:0429 2014-04-23
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 Server (jbossweb) RHSA-2014:0343 2014-03-31
Red Hat JBoss Enterprise Application Platform 6.2 RHSA-2014:0345 2014-03-31
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server (jbossweb) RHSA-2014:0344 2014-03-31
Red Hat JBoss Data Grid 6.2 RHSA-2014:0374 2014-04-03
Red Hat JBoss Data Virtualization 6.0 RHSA-2014:0458 2014-04-30
Red Hat Enterprise Linux 7 (tomcat) RHSA-2014:0686 2014-06-10
Red Hat JBoss Web Server 2.0 RHSA-2014:0528 2014-05-21
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 Server (tomcat7) RHSA-2014:0526 2014-05-21
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 Server (tomcat6) RHSA-2014:0525 2014-05-21
Red Hat JBoss Operations Network 3.2 RHSA-2014:0511 2014-05-15
Unless explicitly stated as not affected, all previous versions of packages in any minor update stream of a product listed here should be assumed vulnerable, although may not have been subject to full analysis.
Last Modified