cbcvebase.
CVE-2021-30640
published 2021-07-12

CVE-2021-30640: A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the…

medium6.5CVSS 3.1
AVNACHPRNUINSUCLIHAN
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.

Affected

18 ranges
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat>= 10.0.0 < 10.0.610.0.6
apachetomcat>= 7.0.0 < 7.0.1097.0.109
apachetomcat>= 8.5.0 < 8.5.668.5.66
apachetomcat>= 9.0.0 < 9.0.469.0.46
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiantomcat9< tomcat9 9.0.43-2 (bookworm)tomcat9 9.0.43-2 (bookworm)
oraclecommunications_cloud_native_core_policy
oraclecommunications_diameter_signaling_router8.0.0 – 8.5.0
oraclecommunications_pricing_design_center
oraclehospitality_cruise_shipboard_property_management_system
oracletekelec_platform_distribution7.4.0 – 7.7.1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
osv6.5MEDIUM