Information disclosure in Apache Tomcat - CVE-2021-24122

 

Information disclosure in Apache Tomcat - CVE-2021-24122

Published: January 14, 2021 / Updated: January 18, 2021


Vulnerability identifier: #VU49570
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-24122
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to JSP source code disclosure in some configurations, when serving resources from a network location using the NTFS file system. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances.A remote attacker can send a specially crafted request to the application and view the JSP source code.


Affected software

Apache Tomcat
SUSE Manager Retail Branch Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP
openEuler
IBM UrbanCode Release
Oracle Agile PLM Framework
Storage Copy Data Management
tomcat6-lib
tomcat6-webapps
tomcat6-servlet-2_5-api
tomcat6-jsp-2_1-api
tomcat6-javadoc
tomcat6-docs-webapp
tomcat6-admin-webapps
tomcat6
tomcat-help
tomcat-jsvc
tomcat
tomcat-webapps
tomcat-servlet-4_0-api
tomcat-admin-webapps
tomcat-el-3_0-api
tomcat-jsp-2_3-api
tomcat-lib

How to mitigate CVE-2021-24122

Install updates from vendor's website.

Apache Tomcat - addressed in versions 7.0.107, 8.5.60, 9.0.40, 10.0.0-M10
IBM UrbanCode Release - update to 6.2.5.3
Storage Copy Data Management - update to 2.2.26.0
tomcat6-lib - update to 6.0.53-0.57.19.1
tomcat6-webapps - update to 6.0.53-0.57.19.1
tomcat6-servlet-2_5-api - update to 6.0.53-0.57.19.1
tomcat6-jsp-2_1-api - update to 6.0.53-0.57.19.1
tomcat6-javadoc - update to 6.0.53-0.57.19.1
tomcat6-docs-webapp - update to 6.0.53-0.57.19.1
tomcat6-admin-webapps - update to 6.0.53-0.57.19.1
tomcat6 - update to 6.0.53-0.57.19.1
tomcat-help - update to 9.0.10-17
tomcat-jsvc - update to 9.0.10-17
tomcat - update to 9.0.10-17
tomcat-webapps - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-admin-webapps - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-el-3_0-api - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-jsp-2_3-api - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-lib - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1

External References

Related Security Bulletins