Improper Input Validation vulnerability in Apache Tomcat (CVE-2023-38545) could potentially lead to request smuggling.

book

Article ID: 100062729

calendar_today

Updated On:

Description

Error Message

None

Cause

Apache Tomcat source code issue.

Resolution

There are no plans to address this issue by way of a patch or hotfix in earlier versions of the software at the present time.  However, the issue has been addressed in the revision of the product specified at the end of this article. 
 
Please contact your Veritas Sales representative or the Veritas Sales group for upgrade information including upgrade eligibility to the release containing the resolution for this issue.

eDiscovery Platform version 10.2.5 addresses this vulnerability with an updated version of Apache Tomcat 9.0.83.

Issue/Introduction

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.