CVE-2021-30640Medium· 6.5▾ SunlitA vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
9.9%
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
tomcat >= 7.0.0, < 7.0.109tomcat >= 8.5.0, < 8.5.66tomcat >= 9.0.0, < 9.0.46tomcat >= 10.0.0, < 10.0.6communications_cloud_native_core_policy = 1.14.0communications_diameter_signaling_router >= 8.0.0, <= 8.5.0communications_pricing_design_center = 12.0.0.3.0hospitality_cruise_shipboard_property_management_system = 20.1.0tekelec_platform_distribution >= 7.4.0, <= 7.7.1debian_linux = 9.0debian_linux = 10.0debian_linux = 11.0Upgrade past the affected range:
tomcat 10.0.6Connected by shared product, vendor, weakness, or advisory.
CVE-2020-17527High· 7.5While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the…
CVE-2016-0762Medium· 5.9The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist
CVE-2021-33037Medium· 5.3Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse pr…
CVE-2021-25329High· 7.0The fix for CVE-2020-9484 was incomplete
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…
CVE-2020-13935High· 7.5The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104