Improper Authentication in Apache Tomcat - CVE-2021-30640

 

Improper Authentication in Apache Tomcat - CVE-2021-30640

Published: July 29, 2021


Vulnerability identifier: #VU55417
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30640
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in the JNDI Realm when processing authentication requests. A remote attacker can authenticate using variations of a valid user name and bypass some of the protection provided by the LockOut Realm.


Affected software

Apache Tomcat
JBoss Web Server
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
Ubuntu
openEuler
Traffix SDC
IBM Tivoli Application Dependency Discovery Manager
IBM Rational Build Forge
tomcat9 (Debian package)
Tomcat
javapackages-tools
tomcat
tomcat-help
tomcat-jsvc
tomcat9-common (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
libtomcat9-embed-java (Ubuntu package)
tomcat-lib
tomcat-admin-webapps
tomcat-docs-webapp
tomcat-el-3_0-api
tomcat-javadoc
tomcat-webapps
tomcat-servlet-4_0-api
tomcat-jsp-2_3-api
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)

How to mitigate CVE-2021-30640

Install updates from vendor's website.

Apache Tomcat - addressed in versions 7.0.109, 8.5.66, 9.0.46, 10.0.6
JBoss Web Server - update to 5.6.0
IBM Rational Build Forge - update to 8.0.0.22
tomcat9 (Debian package) - addressed in versions 9.0.31-1~deb10u5, 9.0.31-1~deb10u6, 9.0.43-2~deb11u2
Tomcat - update to D.9.0.87.01
javapackages-tools - update to 2.0.1-13.1
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
tomcat - update to 9.0.10-20
tomcat-help - update to 9.0.10-20
tomcat-jsvc - update to 9.0.10-20
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9 (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat-lib - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-admin-webapps - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-docs-webapp - update to 9.0.36-3.71.1
tomcat-el-3_0-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-javadoc - update to 9.0.36-3.71.1
tomcat-webapps - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-jsp-2_3-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1

External References

Related Security Bulletins