Resource management error in Apache Tomcat - CVE-2021-25122

 

Resource management error in Apache Tomcat - CVE-2021-25122

Published: March 1, 2021


Vulnerability identifier: #VU51014
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-25122
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to improper management of internal resources within the application when processing new h2c connection requests. A remote attacker can send specially crafted requests to the server and obtain contents of HTTP responses, served to other users.


Affected software

Apache Tomcat
JBoss Web Server
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
Ubuntu
openEuler
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Traffix SDC
IBM Qradar SIEM
MySQL Enterprise Monitor
Oracle Database Server
tomcat9 (Debian package)
tomcat8-docs (Ubuntu package)
tomcat8 (Ubuntu package)
libtomcat8-java (Ubuntu package)
tomcat9 (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9-docs (Ubuntu package)
tomcat
tomcat-help
tomcat-jsvc
tomcat9-common (Ubuntu package)
libtomcat9-embed-java (Ubuntu package)
tomcat-admin-webapps
tomcat-el-3_0-api
tomcat-jsp-2_3-api
tomcat-lib
tomcat-servlet-4_0-api
tomcat-webapps
tomcat-docs-webapp
tomcat-javadoc
IBM Engineering Requirements Management DOORS Next
Oracle Communications Instant Messaging Server
Oracle Managed File Transfer
Instantis EnterpriseTrack
Oracle Graph Server and Client
Dell PowerPath Management Appliance
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC VxRail Appliance

How to mitigate CVE-2021-25122

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.63, 9.0.43, 10.0.2
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 8, 7.4.3 Fix Pack 1
MySQL Enterprise Monitor - update to 8.0.24
tomcat9 (Debian package) - update to 9.0.31-1~deb10u4
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
tomcat8-docs (Ubuntu package) - update to Ubuntu Pro
tomcat8 (Ubuntu package) - update to Ubuntu Pro
libtomcat8-java (Ubuntu package) - update to Ubuntu Pro
tomcat9 (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2, 9.0.31-1ubuntu0.6
libtomcat9-java (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2, 9.0.31-1ubuntu0.6
tomcat9-docs (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
Dell PowerPath Management Appliance - update to 3.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
JBoss Web Server - update to 5.5.0
Dell EMC VxRail Appliance - update to 7.0.240
tomcat - update to 9.0.10-18
tomcat-help - update to 9.0.10-18
tomcat-jsvc - update to 9.0.10-18
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat-admin-webapps - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-el-3_0-api - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-jsp-2_3-api - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-lib - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-webapps - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-docs-webapp - update to 9.0.36-3.64.1
tomcat-javadoc - update to 9.0.36-3.64.1

External References

Related Security Bulletins