Information disclosure in Apache Tomcat - CVE-2021-43980

 

Information disclosure in Apache Tomcat - CVE-2021-43980

Published: September 28, 2022


Vulnerability identifier: #VU67714
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43980
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to incorrect implementation of blocking reads and writes. A remote attacker can trigger a concurrency bug and force client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.


Affected software

Apache Tomcat
Debian Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP
openEuler
IBM UrbanCode Release
IBM Rational Build Forge
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Control Center
UCD - IBM UrbanCode Deploy
IBM Engineering Requirements Management DOORS Next
Storage Copy Data Management
UrbanCode Build
Tomcat
tomcat8
tomcat
tomcat-admin-webapps
tomcat-docs-webapp
tomcat-el-3_0-api
tomcat-javadoc
tomcat-jsp-2_3-api
tomcat-lib
tomcat-servlet-4_0-api
tomcat-webapps
tomcat9 (Debian package)
tomcat9
tomcat-jsvc
tomcat-help
RecoverPoint for VMs

How to mitigate CVE-2021-43980

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.78, 9.0.62, 10.0.20, 10.1.0-M14
IBM UrbanCode Release - update to 6.2.5.8
IBM Rational Build Forge - update to 8.0.0.24
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Tomcat - update to D.9.0.87.01
Netcool Operations Insight - update to 1.6.9
Storage Copy Data Management - update to 2.2.23.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.0
RecoverPoint for VMs - update to 6.0.SP1.P1
UrbanCode Build - update to 6.1.7.7
IBM Sterling Control Center - update to 6.2.1.0.14
UCD - IBM UrbanCode Deploy - addressed in versions 6.2.7.16, 7.0.5.11, 7.1.2.7, 7.2.3.0
tomcat8 - update to 8.5.87-1.92
tomcat - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-admin-webapps - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-docs-webapp - update to 9.0.36-3.90.1
tomcat-el-3_0-api - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-javadoc - update to 9.0.36-3.90.1
tomcat-jsp-2_3-api - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-lib - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-webapps - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat9 (Debian package) - update to 9.0.43-2~deb11u4
tomcat9 - update to 9.0.71-1
tomcat-jsvc - addressed in versions 9.0.96-1, 9.0.96-2
tomcat-help - addressed in versions 9.0.96-1, 9.0.96-2
tomcat - addressed in versions 9.0.96-1, 9.0.96-2

External References

Related Security Bulletins