cbcvebase.
CVE-2021-25122
published 2021-03-01

CVE-2021-25122: When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat
apachetomcat
apachetomcat8.5.0 – 8.5.61
apachetomcat9.0.0 – 9.0.41
apache_software_foundationapache_tomcat>= Apache Tomcat 10 < 10.0.210.0.2
apache_software_foundationapache_tomcat>= Apache Tomcat 8.5 < 8.5.628.5.62
apache_software_foundationapache_tomcat>= Apache Tomcat 9 < 9.0.429.0.42
debiandebian_linux
debiandebian_linux
debiantomcat9< tomcat9 9.0.43-1 (bookworm)tomcat9 9.0.43-1 (bookworm)
oracleagile_plm
oracleagile_plm
oraclecommunications_cloud_native_core_policy
oraclecommunications_cloud_native_core_security_edge_protection_proxy
oraclecommunications_instant_messaging_server
oracledatabase
oracledatabase
oracledatabase
oraclegraph_server_and_client< 21.3.021.3.0
oraclegraph_server_and_client
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oraclemanaged_file_transfer

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH