Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-25122


When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.


Published

2021-03-01T12:15:13.793

Last Modified

2024-11-21T05:54:23.690

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache tomcat ≤ 8.5.61 Yes
Application apache tomcat ≤ 9.0.41 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Application apache tomcat 10.0.0 Yes
Operating System debian debian_linux 9.0 Yes
Operating System debian debian_linux 10.0 Yes
Application oracle agile_plm 9.3.3 Yes
Application oracle agile_plm 9.3.6 Yes
Application oracle communications_cloud_native_core_policy 1.14.0 Yes
Application oracle communications_cloud_native_core_security_edge_protection_proxy 1.6.0 Yes
Application oracle communications_instant_messaging_server 10.0.1.5.0 Yes
Application oracle database 12.2.0.1 Yes
Application oracle database 19c Yes
Application oracle database 21c Yes
Application oracle graph_server_and_client < 21.3.0 Yes
Application oracle graph_server_and_client 21.3.0 Yes
Application oracle instantis_enterprisetrack 17.1 Yes
Application oracle instantis_enterprisetrack 17.2 Yes
Application oracle instantis_enterprisetrack 17.3 Yes
Application oracle managed_file_transfer 12.2.1.3.0 Yes
Application oracle managed_file_transfer 12.2.1.4.0 Yes
Application oracle mysql_enterprise_monitor ≤ 8.0.23 Yes
Application oracle siebel_ui_framework ≤ 21.9 Yes

References