A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
2021-07-12T15:15:08.367
2024-11-21T06:04:20.893
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | tomcat | < 7.0.109 | Yes |
Application | apache | tomcat | < 8.5.66 | Yes |
Application | apache | tomcat | < 9.0.46 | Yes |
Application | apache | tomcat | < 10.0.6 | Yes |
Application | oracle | communications_cloud_native_core_policy | 1.14.0 | Yes |
Application | oracle | communications_diameter_signaling_router | ≤ 8.5.0 | Yes |
Application | oracle | communications_pricing_design_center | 12.0.0.3.0 | Yes |
Application | oracle | hospitality_cruise_shipboard_property_management_system | 20.1.0 | Yes |
Application | oracle | tekelec_platform_distribution | ≤ 7.7.1 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |