Improper Handling of Exceptional Conditions in Apache Tomcat - CVE-2021-30639
Published: July 29, 2021
Vulnerability identifier: #VU55422
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30639
CWE-ID: CWE-755
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error management within the application when handling unexpected connection termination. A remote attacker can drop connection with the Apache Tomcat server, which triggers a non-blocking I/O error and causes all requests, handled by that request object, to fail. As a result, a remote attacker can initiate and drop connections to the server and perform a denial of service attack.Affected software
Apache Tomcat
Gentoo Linux
Big Data Spatial and Graph
Traffix SDC
IBM App Connect Professional
IBM UrbanCode Release
Siebel Apps - Marketing
Tomcat
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Gentoo Linux
Big Data Spatial and Graph
Traffix SDC
IBM App Connect Professional
IBM UrbanCode Release
Siebel Apps - Marketing
Tomcat
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
How to mitigate CVE-2021-30639
Install updates from vendor's website.
Apache Tomcat - addressed in versions 8.5.65, 9.0.45, 10.0.5
IBM UrbanCode Release - update to 6.2.5.5
Tomcat - update to D.9.0.87.01
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
IBM UrbanCode Release - update to 6.2.5.5
Tomcat - update to D.9.0.87.01
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
External References
- https://lists.apache.org/thread.html/rd84fae1f474597bdf358f5bdc0a5c453c507bd527b83e8be6b5ea3f4%40%3Cannounce.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r79a7c019712b39aedf7cf4da9276d80610f04441b2a4f6506cb2daaf@%3Cusers.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r79a7c019712b39aedf7cf4da9276d80610f04441b2a4f6506cb2daaf@%3Cdev.tomcat.apache.org%3E
Related Security Bulletins
- Remote denial of service in Apache Tomcat
- Denial of service in Apache Tomcat component in Traffix SDC
- Multiple vulnerabilities in Oracle Big Data Spatial and Graph
- Improper Handling of Exceptional Conditions in IBM UrbanCode Release
- Gentoo update for Apache Tomcat
- Denial of service in App Connect Professional
- Multiple vulnerabilities in Siebel Apps - Marketing
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- HP-UX update for Tomcat