Information disclosure in Apache Tomcat - CVE-2021-24122
Published: January 14, 2021 / Updated: January 18, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to JSP source code disclosure in some configurations, when serving resources from a network location using the NTFS file system. The root cause was the unexpected behaviour of the JRE API
File.getCanonicalPath() which in turn was caused by the inconsistent
behaviour of the Windows API (FindFirstFileW) in some circumstances.A remote attacker can send a specially crafted request to the application and view the JSP source code.
Affected software
SUSE Manager Retail Branch Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP
openEuler
IBM UrbanCode Release
Oracle Agile PLM Framework
Storage Copy Data Management
tomcat6-lib
tomcat6-webapps
tomcat6-servlet-2_5-api
tomcat6-jsp-2_1-api
tomcat6-javadoc
tomcat6-docs-webapp
tomcat6-admin-webapps
tomcat6
tomcat-help
tomcat-jsvc
tomcat
tomcat-webapps
tomcat-servlet-4_0-api
tomcat-admin-webapps
tomcat-el-3_0-api
tomcat-jsp-2_3-api
tomcat-lib
How to mitigate CVE-2021-24122
IBM UrbanCode Release - update to 6.2.5.3
Storage Copy Data Management - update to 2.2.26.0
tomcat6-lib - update to 6.0.53-0.57.19.1
tomcat6-webapps - update to 6.0.53-0.57.19.1
tomcat6-servlet-2_5-api - update to 6.0.53-0.57.19.1
tomcat6-jsp-2_1-api - update to 6.0.53-0.57.19.1
tomcat6-javadoc - update to 6.0.53-0.57.19.1
tomcat6-docs-webapp - update to 6.0.53-0.57.19.1
tomcat6-admin-webapps - update to 6.0.53-0.57.19.1
tomcat6 - update to 6.0.53-0.57.19.1
tomcat-help - update to 9.0.10-17
tomcat-jsvc - update to 9.0.10-17
tomcat - update to 9.0.10-17
tomcat-webapps - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-admin-webapps - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-el-3_0-api - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-jsp-2_3-api - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-lib - addressed in versions 9.0.36-3.79.1, 9.0.36-4.58.1
External References
- http://www.openwall.com/lists/oss-security/2021/01/14/1
- https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52@%3Cannounce.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r7382e1e35b9bc7c8f320b90ad77e74c13172d08034e20c18000fe710@%3Cdev.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r776c64337495bf28b7d5597268114a888e3fad6045c40a0da0c66d4d@%3Cdev.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r7e0bb9ea415724550e2b325e143b23e269579e54d66fcd7754bd0c20@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rb32a73b7cb919d4f44a2596b6b951274c0004fc8b0e393d6829a45f9@%3Cusers.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rca833c6d42b7b9ce1563488c0929f29fcc95947d86e5e740258c8937@%3Cdev.tomcat.apache.org%3E
Related Security Bulletins
- Information disclosure in Apache Tomcat
- Multiple vulnerabilities in Oracle Agile PLM Framework
- Multiple vulnerabilities in IBM UrbanCode Release
- SUSE update for tomcat
- SUSE update for tomcat6
- SUSE update for tomcat
- openEuler 20.03 LTS SP1 update for tomcat
- Multiple vulnerabilities in IBM Storage Copy Data Management