CVE-2021-25122
published 2021-03-01CVE-2021-25122: When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request…
PriorityP356high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
18.11%
96.9th percentile
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | 8.5.0 – 8.5.61 | — |
| apache | tomcat | 9.0.0 – 9.0.41 | — |
| apache_software_foundation | apache_tomcat | >= Apache Tomcat 10 < 10.0.2 | 10.0.2 |
| apache_software_foundation | apache_tomcat | >= Apache Tomcat 8.5 < 8.5.62 | 8.5.62 |
| apache_software_foundation | apache_tomcat | >= Apache Tomcat 9 < 9.0.42 | 9.0.42 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.43-1 (bookworm) | tomcat9 9.0.43-1 (bookworm) |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| oracle | communications_instant_messaging_server | — | — |
| oracle | database | — | — |
| oracle | database | — | — |
| oracle | database | — | — |
| oracle | graph_server_and_client | < 21.3.0 | 21.3.0 |
| oracle | graph_server_and_client | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | managed_file_transfer | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tomcat8, tomcat9 vulnerabilities
osv·2024-08-01·CVSS 7.0
CVE-2020-9484 [HIGH] tomcat8, tomcat9 vulnerabilities
tomcat8, tomcat9 vulnerabilities
It was discovered that Tomcat incorrectly handled certain uncommon
PersistenceManager with FileStore configurations. A remote attacker could
possibly use this issue to execute arbitrary code. This issue only affected
tomcat8 for Ubuntu 18.04 LTS (CVE-2020-9484)
It was discovered that Tomcat incorrectly handled certain HTTP/2 connection
requests. A remote attacker could use this issue to obtain wrong responses
possibly containing sensitive information. This issue only affected tomcat8
for Ubuntu 18.04 LTS (CVE-2021-25122)
Thomas Wozenilek discovered that Tomcat incorrectly handled certain TLS
packets. A remote attacker could possibly use this issue to cause a denial
of service. This issue only affected tomcat8 for Ubuntu 18.04 LTS
(CVE-2021-41079)
Trung
OSV
tomcat9 vulnerabilities
osv·2022-03-31·CVSS 4.3
CVE-2020-13943 [MEDIUM] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that Tomcat incorrectly performed input verification.
A remote attacker could possibly use this issue to intercept sensitive
information. (CVE-2020-13943, CVE-2020-17527, CVE-2021-25122, CVE-2021-30640)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-33037)
It was discovered that Tomcat did not properly validate the input length. An
attacker could possibly use this to trigger an infinite loop, resulting in a
denial of service. (CVE-2021-25329, CVE-2021-41079)
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
osv·2021-06-16
CVE-2021-25122 [HIGH] Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
ghsa·2021-06-16
CVE-2021-25122 [HIGH] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
OSV
CVE-2021-25122: When responding to new h2c connection requests, Apache Tomcat versions 10
osv·2021-03-01·CVSS 7.5
CVE-2021-25122 [HIGH] CVE-2021-25122: When responding to new h2c connection requests, Apache Tomcat versions 10
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2024-08-01·CVSS 7.0
CVE-2020-9484 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly handled certain uncommon
PersistenceManager with FileStore configurations. A remote attacker could
possibly use this issue to execute arbitrary code. This issue only affected
tomcat8 for Ubuntu 18.04 LTS (CVE-2020-9484)
It was discovered that Tomcat incorrectly handled certain HTTP/2 connection
requests. A remote attacker could use this issue to obtain wrong responses
possibly containing sensitive information. This issue only affected tomcat8
for Ubuntu 18.04 LTS (CVE-2021-25122)
Thomas Wozenilek discovered that Tomcat incorrectly handled certain TLS
packets. A remote attacker could possibly use this issue to cause a denial
of service. This issue only affected
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2022-03-31·CVSS 4.3
CVE-2021-33037 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly performed input verification.
A remote attacker could possibly use this issue to intercept sensitive
information. (CVE-2020-13943, CVE-2020-17527, CVE-2021-25122, CVE-2021-30640)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-33037)
It was discovered that Tomcat did not properly validate the input length. An
attacker could possibly use this to trigger an infinite loop, resulting in a
denial of service. (CVE-2021-25329, CVE-2021-41079)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Communications Applications Risk Matrix: DBPlugin (Apache Tomcat) — CVE-2021-25122
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2021-25122 [HIGH] Oracle Oracle Communications Applications Risk Matrix: DBPlugin (Apache Tomcat) — CVE-2021-25122
Oracle Oracle Communications Applications Risk Matrix: DBPlugin (Apache Tomcat) vulnerability
CVE: CVE-2021-25122
CVSS: 7.5
Protocol: XMPP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Database Enterprise Edition (Apache Tomcat) — CVE-2021-25122
vendor_oracle·2021-10-15·CVSS 7.5
CVE-2021-25122 [HIGH] Oracle Oracle Database Server Risk Matrix: Oracle Database Enterprise Edition (Apache Tomcat) — CVE-2021-25122
Oracle Oracle Database Server Risk Matrix: Oracle Database Enterprise Edition (Apache Tomcat) vulnerability
CVE: CVE-2021-25122
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: HTTP Server (Apache Tomcat) — CVE-2021-25122
vendor_oracle·2021-07-15·CVSS 7.5
CVE-2021-25122 [HIGH] Oracle Oracle Construction and Engineering Risk Matrix: HTTP Server (Apache Tomcat) — CVE-2021-25122
Oracle Oracle Construction and Engineering Risk Matrix: HTTP Server (Apache Tomcat) vulnerability
CVE: CVE-2021-25122
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Red Hat
tomcat: Request mix-up with h2c
vendor_redhat·2021-03-01·CVSS 7.5
CVE-2021-25122 [HIGH] CWE-200 tomcat: Request mix-up with h2c
tomcat: Request mix-up with h2c
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
A flaw was found in Apache Tomcat. When responding to new h2c connection requests, Apache Tomcat could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request. The highest threat from this vulnerability is to data confidentiality.
Statement: Red Hat Enterprise Linux 8's Identity Management and Certificate System are using a vulnerable version of Tomcat
Debian
CVE-2021-25122: tomcat9 - When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1...
vendor_debian·2021·CVSS 7.5
CVE-2021-25122 [HIGH] CVE-2021-25122: tomcat9 - When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1...
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
Scope: local
bookworm: resolved (fixed in 9.0.43-1)
bullseye: resolved (fixed in 9.0.43-1)
forky: resolved (fixed in 9.0.43-1)
sid: resolved (fixed in 9.0.43-1)
trixie: resolved (fixed in 9.0.43-1)
Apache
Apache tomcat: CVE-2021-25122
vendor_apache·CVSS 7.5
CVE-2021-25122 [HIGH] Apache tomcat: CVE-2021-25122
Apache tomcat: CVE-2021-25122
When responding to new h2c connection requests, Apache Tomcat could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request. This was fixed with commit bb0e7c1e . This issue was identified by the Apache Tomcat Security team on 11 January 2021. The issue was made public on 1 March 2021. Affects: 8.5.0 to 8.5.61 17 November 2020 Fixed in Apache Tomcat 8.5.60 Important: Information disclosure
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2021/03/01/1https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rcd90bf36b1877e1310b87ecd14ed7bbb15da52b297efd9f0e7253a3b%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rd0463f9a5cbc02a485404c4b990f0da452e5ac5c237808edba11c947%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00018.htmlhttps://security.gentoo.org/glsa/202208-34https://security.netapp.com/advisory/ntap-20210409-0002/https://www.debian.org/security/2021/dsa-4891https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://www.openwall.com/lists/oss-security/2021/03/01/1https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rcd90bf36b1877e1310b87ecd14ed7bbb15da52b297efd9f0e7253a3b%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rd0463f9a5cbc02a485404c4b990f0da452e5ac5c237808edba11c947%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00018.htmlhttps://security.gentoo.org/glsa/202208-34https://security.netapp.com/advisory/ntap-20210409-0002/https://www.debian.org/security/2021/dsa-4891https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-03-01
Published