CVE-2021-30640
published 2021-07-12CVE-2021-30640: A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the…
PriorityP346medium6.5CVSS 3.1
AVNACHPRNUINSUCLIHAN
EPSS
9.89%
95.0th percentile
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.0.0 < 10.0.6 | 10.0.6 |
| apache | tomcat | >= 7.0.0 < 7.0.109 | 7.0.109 |
| apache | tomcat | >= 8.5.0 < 8.5.66 | 8.5.66 |
| apache | tomcat | >= 9.0.0 < 9.0.46 | 9.0.46 |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.43-2 (bookworm) | tomcat9 9.0.43-2 (bookworm) |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.5.0 | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | hospitality_cruise_shipboard_property_management_system | — | — |
| oracle | tekelec_platform_distribution | 7.4.0 – 7.7.1 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv6.5MEDIUM
vendor_apache6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tomcat9 vulnerabilities
osv·2022-03-31·CVSS 4.3
CVE-2020-13943 [MEDIUM] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that Tomcat incorrectly performed input verification.
A remote attacker could possibly use this issue to intercept sensitive
information. (CVE-2020-13943, CVE-2020-17527, CVE-2021-25122, CVE-2021-30640)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-33037)
It was discovered that Tomcat did not properly validate the input length. An
attacker could possibly use this to trigger an infinite loop, resulting in a
denial of service. (CVE-2021-25329, CVE-2021-41079)
OSV
Authentication Bypass by Alternate Name in Apache Tomcat
osv·2021-08-13
CVE-2021-30640 [MEDIUM] Authentication Bypass by Alternate Name in Apache Tomcat
Authentication Bypass by Alternate Name in Apache Tomcat
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
GHSA
Authentication Bypass by Alternate Name in Apache Tomcat
ghsa·2021-08-13
CVE-2021-30640 [MEDIUM] CWE-116 Authentication Bypass by Alternate Name in Apache Tomcat
Authentication Bypass by Alternate Name in Apache Tomcat
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
OSV
CVE-2021-30640: A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of t
osv·2021-07-12·CVSS 6.5
CVE-2021-30640 [MEDIUM] CVE-2021-30640: A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of t
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2022-03-31·CVSS 4.3
CVE-2021-33037 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly performed input verification.
A remote attacker could possibly use this issue to intercept sensitive
information. (CVE-2020-13943, CVE-2020-17527, CVE-2021-25122, CVE-2021-30640)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-33037)
It was discovered that Tomcat did not properly validate the input length. An
attacker could possibly use this to trigger an infinite loop, resulting in a
denial of service. (CVE-2021-25329, CVE-2021-41079)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Communications Risk Matrix: Console (Apache Tomcat) — CVE-2021-30640
vendor_oracle·2021-10-15·CVSS 6.5
CVE-2021-30640 [MEDIUM] Oracle Oracle Communications Risk Matrix: Console (Apache Tomcat) — CVE-2021-30640
Oracle Oracle Communications Risk Matrix: Console (Apache Tomcat) vulnerability
CVE: CVE-2021-30640
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Red Hat
tomcat: JNDI realm authentication weakness
vendor_redhat·2021-07-12·CVSS 6.5
CVE-2021-30640 [MEDIUM] CWE-287 tomcat: JNDI realm authentication weakness
tomcat: JNDI realm authentication weakness
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
Statement: Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of OpenStack Platform 14 and is only receiving security fixes for Critical flaws.
Package: tomcat (Red Hat Decision Manager 7) - Not affected
Package: tomcat6 (Red Hat Enterprise Linux 6) - Not affected
Package: tomcat (Red Hat Enterprise Linux 7) - Not affected
Package: pki-deps:10.6/pki-servlet-engine (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2021-30640: tomcat9 - A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authent...
vendor_debian·2021·CVSS 6.5
CVE-2021-30640 [MEDIUM] CVE-2021-30640: tomcat9 - A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authent...
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
Scope: local
bookworm: resolved (fixed in 9.0.43-2)
bullseye: resolved (fixed in 9.0.43-2~deb11u1)
forky: resolved (fixed in 9.0.43-2)
sid: resolved (fixed in 9.0.43-2)
trixie: resolved (fixed in 9.0.43-2)
Apache
Apache tomcat: CVE-2021-30640
vendor_apache·CVSS 6.5
CVE-2021-30640 [MEDIUM] Apache tomcat: CVE-2021-30640
Apache tomcat: CVE-2021-30640
Queries made by the JNDI Realm did not always correctly escape parameters. Parameter values could be sourced from user provided data (eg user names) as well as configuration data provided by an administrator. In limited circumstances it was possible for users to authenticate using variations of their user name and/or to bypass some of the protection provided by the LockOut Realm. This was fixed with commits 24dfb300 , 0a272b00 , c9f21a2a , 4e86b4ea , 79580e7f , d3407672 , 6a9129ac and ad22db64 . This issue was reported publicly as 65224 . Affects: 8.5.0 to 8.5.65 6 April 2021 Fixed in Apache Tomcat 8.5.65 Important: Denial of Service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-30640 tomcat: JNDI realm authentication weakness
bugzilla·2021-07-12·CVSS 6.5
CVE-2021-30640 [MEDIUM] CVE-2021-30640 tomcat: JNDI realm authentication weakness
CVE-2021-30640 tomcat: JNDI realm authentication weakness
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
Reference:
https://lists.apache.org/thread.html/r59f9ef03929d32120f91f4ea7e6e79edd5688d75d0a9b65fd26d1fe8%40%3Cannounce.tomcat.apache.org%3E
Discussion:
Created tomcat tracking bugs for this issue:
Affects: fedora-all [bug 1981545]
---
This issue has been addressed in the following products:
Red Hat JBoss Web Server
Via RHSA-2021:4863 https://access.redhat.com/errata/RHSA-2021:4863
---
This issue has been addressed in the following products:
arXiv
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
arxiv_fulltext·2024-09-04
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
Fangyuan Zhang,
Lingling Fan*,
Sen Chen,
Miaoying Cai,
Sihan Xu,
and Lida Zhao
Fangyuan Zhang and Miaoying Cai are with DISSec, NDST, College of Computer Science, Nankai University, China. Emails: \fangyuanzhang, miaoyingcai\@mail.nankai.edu.cn.
Lingling Fan (Corresponding author) and Sihan Xu are with DISSec, NDST, College of Cyber Science, Nankai University, China. Emails: \linglingfan, xusihan\@nankai.edu.cn.
Sen Chen is with the College of Intelligence and Computing, Tianjin University, China. Email: [email protected].
Lida Zhao is with School of Computer Science and Engineering, Nanyang Technological University. Email: [email protected].
Journal of \ Class Files, Vol. XX,
https://lists.apache.org/thread.html/r59f9ef03929d32120f91f4ea7e6e79edd5688d75d0a9b65fd26d1fe8%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/08/msg00009.htmlhttps://security.gentoo.org/glsa/202208-34https://security.netapp.com/advisory/ntap-20210827-0007/https://www.debian.org/security/2021/dsa-4952https://www.debian.org/security/2021/dsa-4986https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://lists.apache.org/thread.html/r59f9ef03929d32120f91f4ea7e6e79edd5688d75d0a9b65fd26d1fe8%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/08/msg00009.htmlhttps://security.gentoo.org/glsa/202208-34https://security.netapp.com/advisory/ntap-20210827-0007/https://www.debian.org/security/2021/dsa-4952https://www.debian.org/security/2021/dsa-4986https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-07-12
Published