CVE-2010-2227

Apache Tomcat 5.5.0-5.5.29, 6.0.0-6.0.27, 7.0.0 beta - Denial of Service via Invalid Transfer-Encoding Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-2227. PoCs published by Steve Jones, including Metasploit module auxiliary/dos/http/apache_tomcat_transfer_encoding.

AI-analyzed exploit summary This Metasploit module exploits a vulnerability in Apache Tomcat (CVE-2010-2227) by sending malformed Transfer-Encoding headers to cause a denial of service (DoS) or information disclosure. It sends multiple crafted HTTP POST requests with an invalid Transfer-Encoding header and an oversized Content-Length to trigger the vulnerability.

Description

Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."

Exploits (1)

metasploit WORKING POC
by Steve Jones · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/http/apache_tomcat_transfer_encoding.rb

This Metasploit module exploits a vulnerability in Apache Tomcat (CVE-2010-2227) by sending malformed Transfer-Encoding headers to cause a denial of service (DoS) or information disclosure. It sends multiple crafted HTTP POST requests with an invalid Transfer-Encoding header and an oversized Content-Length to trigger the vulnerability.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta
No auth needed
Prerequisites: Network access to the target Tomcat server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (48)

Core 48
Core References
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/512272/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42079
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2207
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=136485229118404&w=2
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:177
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3056
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43310
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0581.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/41544
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-7.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050214.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1986
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44183
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0580.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/41025
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050207.html
Various Sources x_refsource_confirm
http://geronimo.apache.org/22x-security-report.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40813
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:176
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42368
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-6.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57126
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18532
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1024180
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-5.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=129070310906557&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/60264
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5002
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0582.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2868
Various Sources x_refsource_confirm
http://geronimo.apache.org/21x-security-report.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42454
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/516397/100/0/threaded
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=139344343412337&w=2
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0583.html

Scores

EPSS 0.8017
EPSS Percentile 99.1%

Details

CWE
CWE-119
Status published
Products (50)
apache/tomcat 5.5.0
apache/tomcat 5.5.1
apache/tomcat 5.5.2
apache/tomcat 5.5.3
apache/tomcat 5.5.4
apache/tomcat 5.5.5
apache/tomcat 5.5.6
apache/tomcat 5.5.7
apache/tomcat 5.5.8
apache/tomcat 5.5.9
... and 40 more
Published Jul 13, 2010
Tracked Since Feb 18, 2026