Deserialization of Untrusted Data in Apache Tomcat - CVE-2021-25329
Published: March 1, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Note, the vulnerability exists due to incomplete fix for #VU28158 and requires a certain specific configuration.
Affected software
JBoss Web Server
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
openEuler
Traffix SDC
IBM Qradar SIEM
tomcat9 (Debian package)
tomcat7 (Ubuntu package)
libtomcat7-java (Ubuntu package)
libservlet3.0-java (Ubuntu package)
tomcat6-servlet-2_5-api
tomcat6-admin-webapps
tomcat6-docs-webapp
tomcat6-javadoc
tomcat6-jsp-2_1-api
tomcat6-lib
tomcat6-webapps
tomcat6
tomcat-docs-webapp
tomcat-lib
tomcat-admin-webapps
tomcat
tomcat-el-3_0-api
tomcat-javadoc
tomcat-jsp-2_3-api
tomcat-servlet-3_1-api
tomcat-webapps
tomcat-help
tomcat-jsvc
tomcat9 (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9-common (Ubuntu package)
libtomcat9-embed-java (Ubuntu package)
tomcat-servlet-4_0-api
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC VxRail Appliance
How to mitigate CVE-2021-25329
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 8, 7.4.3 Fix Pack 1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u4
tomcat7 (Ubuntu package) - update to Ubuntu Pro
libtomcat7-java (Ubuntu package) - update to Ubuntu Pro
libservlet3.0-java (Ubuntu package) - update to Ubuntu Pro
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
JBoss Web Server - update to 5.5.0
tomcat6-servlet-2_5-api - update to 6.0.53-0.57.19.1
tomcat6-admin-webapps - update to 6.0.53-0.57.19.1
tomcat6-docs-webapp - update to 6.0.53-0.57.19.1
tomcat6-javadoc - update to 6.0.53-0.57.19.1
tomcat6-jsp-2_1-api - update to 6.0.53-0.57.19.1
tomcat6-lib - update to 6.0.53-0.57.19.1
tomcat6-webapps - update to 6.0.53-0.57.19.1
tomcat6 - update to 6.0.53-0.57.19.1
Dell EMC VxRail Appliance - update to 7.0.240
tomcat-docs-webapp - addressed in versions 8.0.53-29.46.1, 9.0.36-3.64.1
tomcat-lib - addressed in versions 8.0.53-29.46.1, 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-admin-webapps - addressed in versions 8.0.53-29.46.1, 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat - addressed in versions 8.0.53-29.46.1, 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-el-3_0-api - addressed in versions 8.0.53-29.46.1, 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-javadoc - addressed in versions 8.0.53-29.46.1, 9.0.36-3.64.1
tomcat-jsp-2_3-api - addressed in versions 8.0.53-29.46.1, 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-servlet-3_1-api - update to 8.0.53-29.46.1
tomcat-webapps - addressed in versions 8.0.53-29.46.1, 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat - update to 9.0.10-18
tomcat-help - update to 9.0.10-18
tomcat-jsvc - update to 9.0.10-18
tomcat9 (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Tomcat
- Remote code execution in Apache Tomcat component in F5 Traffix SDC
- Amazon Linux AMI update for tomcat7
- Debian update for tomcat9
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Ubuntu update for tomcat9
- SUSE update for tomcat
- SUSE update for tomcat
- SUSE update for tomcat6
- Gentoo update for Apache Tomcat
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- SUSE update for tomcat
- SUSE update for tomcat
- SUSE update for tomcat
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- openEuler 20.03 LTS SP1 update for tomcat
- Ubuntu update for tomcat7