Resource management error in Apache Tomcat - CVE-2021-25122
Published: March 1, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper management of internal resources within the application when processing new h2c connection requests. A remote attacker can send specially crafted requests to the server and obtain contents of HTTP responses, served to other users.
Affected software
JBoss Web Server
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
Ubuntu
openEuler
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Traffix SDC
IBM Qradar SIEM
MySQL Enterprise Monitor
Oracle Database Server
tomcat9 (Debian package)
tomcat8-docs (Ubuntu package)
tomcat8 (Ubuntu package)
libtomcat8-java (Ubuntu package)
tomcat9 (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9-docs (Ubuntu package)
tomcat
tomcat-help
tomcat-jsvc
tomcat9-common (Ubuntu package)
libtomcat9-embed-java (Ubuntu package)
tomcat-admin-webapps
tomcat-el-3_0-api
tomcat-jsp-2_3-api
tomcat-lib
tomcat-servlet-4_0-api
tomcat-webapps
tomcat-docs-webapp
tomcat-javadoc
IBM Engineering Requirements Management DOORS Next
Oracle Communications Instant Messaging Server
Oracle Managed File Transfer
Instantis EnterpriseTrack
Oracle Graph Server and Client
Dell PowerPath Management Appliance
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC VxRail Appliance
How to mitigate CVE-2021-25122
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 8, 7.4.3 Fix Pack 1
MySQL Enterprise Monitor - update to 8.0.24
tomcat9 (Debian package) - update to 9.0.31-1~deb10u4
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
tomcat8-docs (Ubuntu package) - update to Ubuntu Pro
tomcat8 (Ubuntu package) - update to Ubuntu Pro
libtomcat8-java (Ubuntu package) - update to Ubuntu Pro
tomcat9 (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2, 9.0.31-1ubuntu0.6
libtomcat9-java (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2, 9.0.31-1ubuntu0.6
tomcat9-docs (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
Dell PowerPath Management Appliance - update to 3.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
JBoss Web Server - update to 5.5.0
Dell EMC VxRail Appliance - update to 7.0.240
tomcat - update to 9.0.10-18
tomcat-help - update to 9.0.10-18
tomcat-jsvc - update to 9.0.10-18
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat-admin-webapps - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-el-3_0-api - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-jsp-2_3-api - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-lib - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-webapps - addressed in versions 9.0.36-3.24.1, 9.0.36-3.64.1, 9.0.36-3.79.1, 9.0.36-4.58.1
tomcat-docs-webapp - update to 9.0.36-3.64.1
tomcat-javadoc - update to 9.0.36-3.64.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Tomcat
- Denial of service in Apache Tomcat component in F5 Traffix SDC
- Amazon Linux AMI update for tomcat8
- Debian update for tomcat9
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Resource management error in Instantis EnterpriseTrack
- Resource management error in Oracle Managed File Transfer
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Oracle Database Server
- Multiple vulnerabilities in Oracle Communications Instant Messaging Server
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Ubuntu update for tomcat9
- SUSE update for tomcat
- SUSE update for tomcat
- Gentoo update for Apache Tomcat
- Resource management error in Oracle Graph Server and Client
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in PowerPath Management Appliance
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- SUSE update for tomcat
- SUSE update for tomcat
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- openEuler 20.03 LTS SP1 update for tomcat
- Ubuntu update for tomcat8