Deserialization of Untrusted Data in Apache Tomcat - CVE-2021-25329

 

Deserialization of Untrusted Data in Apache Tomcat - CVE-2021-25329

Published: March 1, 2021


Vulnerability identifier: #VU51012
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-25329
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.

Note, the vulnerability exists due to incomplete fix for #VU28158 and requires a certain specific configuration.


Affected software

Apache Tomcat
JBoss Web Server
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
openEuler
Traffix SDC
IBM Qradar SIEM
tomcat9 (Debian package)
tomcat7 (Ubuntu package)
libtomcat7-java (Ubuntu package)
libservlet3.0-java (Ubuntu package)
tomcat6-servlet-2_5-api
tomcat6-admin-webapps
tomcat6-docs-webapp
tomcat6-javadoc
tomcat6-jsp-2_1-api
tomcat6-lib
tomcat6-webapps
tomcat6
tomcat-docs-webapp
tomcat-lib
tomcat-admin-webapps
tomcat
tomcat-el-3_0-api
tomcat-javadoc
tomcat-jsp-2_3-api
tomcat-servlet-3_1-api
tomcat-webapps
tomcat-help
tomcat-jsvc
tomcat9 (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9-common (Ubuntu package)
libtomcat9-embed-java (Ubuntu package)
tomcat-servlet-4_0-api
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC VxRail Appliance

How to mitigate CVE-2021-25329

Install updates from vendor's website.

Apache Tomcat - addressed in versions 7.0.108, 8.5.63, 9.0.43, 10.0.2
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 8, 7.4.3 Fix Pack 1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u4
tomcat7 (Ubuntu package) - update to Ubuntu Pro
libtomcat7-java (Ubuntu package) - update to Ubuntu Pro
libservlet3.0-java (Ubuntu package) - update to Ubuntu Pro
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
JBoss Web Server - update to 5.5.0
tomcat6-servlet-2_5-api - update to 6.0.53-0.57.19.1
tomcat6-admin-webapps - update to 6.0.53-0.57.19.1
tomcat6-docs-webapp - update to 6.0.53-0.57.19.1
tomcat6-javadoc - update to 6.0.53-0.57.19.1
tomcat6-jsp-2_1-api - update to 6.0.53-0.57.19.1
tomcat6-lib - update to 6.0.53-0.57.19.1
tomcat6-webapps - update to 6.0.53-0.57.19.1
tomcat6 - update to 6.0.53-0.57.19.1
Dell EMC VxRail Appliance - update to 7.0.240
tomcat-docs-webapp - addressed in versions 8.0.53-29.46.1, 9.0.36-3.64.1
tomcat-lib - addressed in versions 8.0.53-29.46.1, 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-admin-webapps - addressed in versions 8.0.53-29.46.1, 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat - addressed in versions 8.0.53-29.46.1, 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-el-3_0-api - addressed in versions 8.0.53-29.46.1, 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-javadoc - addressed in versions 8.0.53-29.46.1, 9.0.36-3.64.1
tomcat-jsp-2_3-api - addressed in versions 8.0.53-29.46.1, 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-servlet-3_1-api - update to 8.0.53-29.46.1
tomcat-webapps - addressed in versions 8.0.53-29.46.1, 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat - update to 9.0.10-18
tomcat-help - update to 9.0.10-18
tomcat-jsvc - update to 9.0.10-18
tomcat9 (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1

External References

Related Security Bulletins