VulnerabilityModified
CVE-2021-30640
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm.
MEDIUM 6.5EPSS 9.89%
Does this matter?
Lower severity and a low EPSS score (9.89%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
- EPSS
- 9.89% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-116
- Affected
- apache/tomcat · oracle/communications cloud native core policy · oracle/communications diameter signaling router · oracle/communications pricing design center · oracle/hospitality cruise shipboard property management system · oracle/tekelec platform distribution · debian/debian linux
- Source
- security@apache.org
References
- https://lists.apache.org/thread.html/r59f9ef03929d32120f91f4ea7e6e79edd5688d75d0a9b65fd26d1fe8%40%3Cannounce.tomcat.apache.org%3EMailing List, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/08/msg00009.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202208-34Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210827-0007/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4952Third Party Advisory
- https://www.debian.org/security/2021/dsa-4986Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://lists.apache.org/thread.html/r59f9ef03929d32120f91f4ea7e6e79edd5688d75d0a9b65fd26d1fe8%40%3Cannounce.tomcat.apache.org%3EMailing List, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/08/msg00009.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202208-34Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210827-0007/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4952Third Party Advisory
- https://www.debian.org/security/2021/dsa-4986Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.