Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-2227

63
FAUCET Score

CVE-2010-2227 is a denial-of-service and information disclosure vulnerability affecting Apache Tomcat versions 5.5.0-5.5.29, 6.0.0-6.0.27, and 7.0.0 beta. It arises from improper handling of invalid Transfer-Encoding headers, leading to buffer recycling issues. With a CVSS score of 6.4 (medium), this vulnerability can be exploited remotely with low complexity, potentially causing application outages or sensitive information disclosure. While not currently on CISA's KEV catalog, there are Metasploit modules available for exploitation, though community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
5.5.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:5.5.0:*:*:*:*:*:*:*
5.5.1CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:5.5.1:*:*:*:*:*:*:*
5.5.2CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:5.5.2:*:*:*:*:*:*:*
5.5.3CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:5.5.3:*:*:*:*:*:*:*
5.5.4CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:5.5.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.4MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
4.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
54.78%
Probability of exploitation in next 30 days
EPSS Percentile
98.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: Apache Tomcat Transfer-Encoding Information Disclosure and DoS · Jul 9, 2010
This CVE's current EPSS score of 0.5478 is in the 99th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 7.0.2
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 5.5.30
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 6.0.28
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jbossweb-0:2.0.0-6.CP14.0jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jbossweb-0:2.0.0-6.CP14.0jpp.ep1.1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEWS 1.0 for RHEL 4Fixed in: tomcat5-0:5.5.28-9.patch_01.jdk6.ep5.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEWS 1.0 for RHEL 4Fixed in: tomcat6-0:6.0.24-7.patch_01.jdk6.ep5.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: tomcat5-0:5.5.23-0jpp_4rh.19
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer Suite V.3Fixed in: tomcat5-0:5.5.23-0jpp_21rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: tomcat5-0:5.5.23-0jpp.9.el5_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jbossweb-0:2.0.0-6.CP14.0jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jbossweb-0:2.0.0-6.CP14.0jpp.ep1.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 1 for RHEL 5Fixed in: tomcat5-0:5.5.28-9.patch_01.1.jdk6.ep5.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 1 for RHEL 5Fixed in: tomcat6-0:6.0.24-7.patch_01.jdk6.ep5.el5
View patch
redhatpatch availablevia redhat_api
Product: RHAPS Version 2 for RHEL 4Fixed in: tomcat5-0:5.5.23-0jpp_4rh.17
View patch

Vendor Advisories (2)

mavenGHSA-cxg2-49rq-8gcrmedium

Apache Tomcat does not properly handle an invalid Transfer-Encoding header

May 14, 2022
redhatCVE-2010-2227Important

tomcat: information leak vulnerability in the handling of 'Transfer-Encoding' header

Jul 8, 2010

References

geronimo.apache.org / 21x-security-report.html
geronimo.apache.org / 22x-security-report.html
lists.apple.com / archives/Security-announce/2011//Oct/msg00003.html
lists.fedoraproject.org / pipermail/package-announce/2010-November/050207.html
lists.fedoraproject.org / pipermail/package-announce/2010-November/050214.html
lists.opensuse.org / opensuse-security-announce/2010-09/msg00006.html
marc.info
marc.info
marc.info
secunia.com / advisories/40813
secunia.com / advisories/41025
secunia.com / advisories/42079
secunia.com / advisories/42368
secunia.com / advisories/42454
secunia.com / advisories/43310
secunia.com / advisories/44183
secunia.com / advisories/57126
securitytracker.com / id
exchange.xforce.ibmcloud.com / vulnerabilities/60264
lists.apache.org / thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18532
support.apple.com / kb/HT5002
svn.apache.org / viewvc
Patch
svn.apache.org / viewvc
Patch
svn.apache.org / viewvc
Patch
tomcat.apache.org / security-5.html
Vendor Advisory
tomcat.apache.org / security-6.html
Vendor Advisory
tomcat.apache.org / security-7.html
Vendor Advisory
debian.org / security/2011/dsa-2207
mandriva.com / security/advisories
mandriva.com / security/advisories
novell.com / support/viewContent.do
novell.com / support/viewContent.do
redhat.com / support/errata/RHSA-2010-0580.html
redhat.com / support/errata/RHSA-2010-0581.html
redhat.com / support/errata/RHSA-2010-0582.html
redhat.com / support/errata/RHSA-2010-0583.html
securityfocus.com / archive/1/512272/100/0/threaded
securityfocus.com / archive/1/516397/100/0/threaded
securityfocus.com / bid/41544
vmware.com / security/advisories/VMSA-2011-0003.html
vmware.com / support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
vupen.com / english/advisories/2010/1986
vupen.com / english/advisories/2010/2868
vupen.com / english/advisories/2010/3056