CVE-2021-30640

Aliases:GHSA-36qh-35cm-5w2wBIT-tomcat-2021-30640
Modified
Published: 12 Jul 2021, 14:55
Last modified:03 Aug 2024, 22:40

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.12% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Jul 2021, 14:55
Published
Vulnerability first disclosed
03 Aug 2024, 22:40
Last Modified
Vulnerability information updated

Description

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
  • v2.0MEDIUMScore: 5.8AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 0.12% Percentile: 31%

Techniques & Countermeasures

  • CWE-116Improper Encoding or Escaping of Output

    The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Affected Systems

  • apache software foundationapache tomcat

    Apache Tomcat 10 10.0.0-M1 to 10.0.5 | Apache Tomcat 9 9.0.0.M1 to 9.0.45 | Apache Tomcat 8.5 8.5.0 to 8.5.65 | Apache Tomcat 7 7.0.0 to 7.0.108

  • UnknownTomcat

    ≥ 7.0.0, < 7.0.109 | ≥ 8.5.0, < 8.5.66 | ≥ 9.0.0, < 9.0.46 | ≥ 10.0.0, < 10.0.6

  • debiandebian_linux

    9.0 | 10.0 | 11.0

  • org.apache.tomcattomcat

    ≥ 10.0.0-M1, < 10.0.5 | ≥ 9.0.0M1, < 9.0.45 | ≥ 8.5.0, < 8.5.65

  • oraclecommunications_cloud_native_core_policy

    1.14.0

  • oraclecommunications_diameter_signaling_router

    ≥ 8.0.0, ≤ 8.5.0

  • oraclecommunications_pricing_design_center

    12.0.0.3.0

  • oraclehospitality_cruise_shipboard_property_management_system

    20.1.0

  • oracletekelec_platform_distribution

    ≥ 7.4.0, ≤ 7.7.1

References (11)