Multiple legacy Apache Tomcat releases are affected by vulnerabilities including HTTP request smuggling (CVE-2005-2090), insecure default SSL cipher suites (CVE-2007-1858), and cross-site scripting in the bundled calendar example (CVE-2006-7196). The request-smuggling flaw affects Tomcat 5.0.19 with Coyote/1.1 and Tomcat 4.1.24 with Coyote/1.0 when conflicting Transfer-Encoding: chunked and Content-Length headers cause request-body data to be forwarded and interpreted as a separate downstream request.
Affected SSL configurations in Tomcat 4.1.28–4.1.31, 5.0.0–5.0.30, and 5.5.0–5.5.17 permit anonymous and other insecure cipher suites, potentially exposing sensitive information. Separately, the cal2.jsp calendar example allows script injection through its time parameter in several Tomcat 4.x, 5.0.x, and 5.5.x releases. Organizations operating these obsolete versions should remove vulnerable example applications, disable weak SSL ciphers, and upgrade to supported Tomcat releases to mitigate cache poisoning, security-control bypass, data exposure, and XSS risks.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2007-1858 was published for insecure default SSL cipher-suite configurations in Apache Tomcat. Affected releases enabled anonymous ciphers that could allow remote attackers to obtain sensitive information or cause other unspecified impacts.
CVE-2006-7196 was published for a cross-site scripting vulnerability in Apache Tomcat's calendar application example. Remote attackers could inject script or HTML through the time parameter supplied to cal2.jsp.
CVE-2005-2090 was published for an HTTP request-smuggling flaw affecting Jakarta Tomcat 5.0.19 with Coyote/1.1 and Tomcat 4.1.24 with Coyote/1.0. Requests containing both Transfer-Encoding: chunked and Content-Length headers could cause request-body data to be forwarded and interpreted as a separate request.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
5 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcesupport.avaya.com
Open sourcesupport.avaya.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.