{"id":"CVE-2021-30640","title":"A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm","summary":"A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","cwe":["CWE-116"],"vendor":"apache","product":"tomcat","affected":["tomcat >= 7.0.0, < 7.0.109","tomcat >= 8.5.0, < 8.5.66","tomcat >= 9.0.0, < 9.0.46","tomcat >= 10.0.0, < 10.0.6","communications_cloud_native_core_policy = 1.14.0","communications_diameter_signaling_router >= 8.0.0, <= 8.5.0","communications_pricing_design_center = 12.0.0.3.0","hospitality_cruise_shipboard_property_management_system = 20.1.0","tekelec_platform_distribution >= 7.4.0, <= 7.7.1","debian_linux = 9.0","debian_linux = 10.0","debian_linux = 11.0"],"patched":["tomcat 10.0.6"],"published":"2021-07-12","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:35.173","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-30640","references":[{"url":"https://lists.apache.org/thread.html/r59f9ef03929d32120f91f4ea7e6e79edd5688d75d0a9b65fd26d1fe8%40%3Cannounce.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/08/msg00009.html","label":"security@apache.org"},{"url":"https://security.gentoo.org/glsa/202208-34","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20210827-0007/","label":"security@apache.org"},{"url":"https://www.debian.org/security/2021/dsa-4952","label":"security@apache.org"},{"url":"https://www.debian.org/security/2021/dsa-4986","label":"security@apache.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r59f9ef03929d32120f91f4ea7e6e79edd5688d75d0a9b65fd26d1fe8%40%3Cannounce.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/08/msg00009.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202208-34","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210827-0007/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2021/dsa-4952","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2021/dsa-4986","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.09886,"epssPercentile":0.95464,"ingestedAt":"2026-10-08T22:11:53.737Z","slug":"CVE-2021-30640","body":"## Overview\n\nA vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.\n\n## Affected\n\n- `tomcat >= 7.0.0, < 7.0.109`\n- `tomcat >= 8.5.0, < 8.5.66`\n- `tomcat >= 9.0.0, < 9.0.46`\n- `tomcat >= 10.0.0, < 10.0.6`\n- `communications_cloud_native_core_policy = 1.14.0`\n- `communications_diameter_signaling_router >= 8.0.0, <= 8.5.0`\n- `communications_pricing_design_center = 12.0.0.3.0`\n- `hospitality_cruise_shipboard_property_management_system = 20.1.0`\n- `tekelec_platform_distribution >= 7.4.0, <= 7.7.1`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tomcat 10.0.6`","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":35.8,"likelihood":2,"exploitation":0,"ransomware":0},"changes":[]}