Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-24122


When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances.


Published

2021-01-14T15:15:13.400

Last Modified

2024-11-21T05:52:23.897

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    CWE-706

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache tomcat ≤ 7.0.106 Yes
Application apache tomcat ≤ 8.5.59 Yes
Application apache tomcat ≤ 9.0.39 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Operating System debian debian_linux 9.0 Yes
Application oracle agile_plm 9.3.3 Yes
Application oracle agile_plm 9.3.6 Yes

References