Information disclosure in Apache Tomcat - CVE-2021-43980
Published: September 28, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to incorrect implementation of blocking reads and writes. A remote attacker can trigger a concurrency bug and force client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
Affected software
Debian Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP
openEuler
IBM UrbanCode Release
IBM Rational Build Forge
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Control Center
UCD - IBM UrbanCode Deploy
IBM Engineering Requirements Management DOORS Next
Storage Copy Data Management
UrbanCode Build
Tomcat
tomcat8
tomcat
tomcat-admin-webapps
tomcat-docs-webapp
tomcat-el-3_0-api
tomcat-javadoc
tomcat-jsp-2_3-api
tomcat-lib
tomcat-servlet-4_0-api
tomcat-webapps
tomcat9 (Debian package)
tomcat9
tomcat-jsvc
tomcat-help
RecoverPoint for VMs
How to mitigate CVE-2021-43980
IBM UrbanCode Release - update to 6.2.5.8
IBM Rational Build Forge - update to 8.0.0.24
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Tomcat - update to D.9.0.87.01
Netcool Operations Insight - update to 1.6.9
Storage Copy Data Management - update to 2.2.23.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.0
RecoverPoint for VMs - update to 6.0.SP1.P1
UrbanCode Build - update to 6.1.7.7
IBM Sterling Control Center - update to 6.2.1.0.14
UCD - IBM UrbanCode Deploy - addressed in versions 6.2.7.16, 7.0.5.11, 7.1.2.7, 7.2.3.0
tomcat8 - update to 8.5.87-1.92
tomcat - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-admin-webapps - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-docs-webapp - update to 9.0.36-3.90.1
tomcat-el-3_0-api - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-javadoc - update to 9.0.36-3.90.1
tomcat-jsp-2_3-api - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-lib - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-webapps - addressed in versions 9.0.36-3.90.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat9 (Debian package) - update to 9.0.43-2~deb11u4
tomcat9 - update to 9.0.71-1
tomcat-jsvc - addressed in versions 9.0.96-1, 9.0.96-2
tomcat-help - addressed in versions 9.0.96-1, 9.0.96-2
tomcat - addressed in versions 9.0.96-1, 9.0.96-2
External References
Related Security Bulletins
- Information disclosure in Apache Tomcat
- Debian update for tomcat9
- SUSE update for tomcat
- SUSE update for tomcat
- SUSE update for tomcat
- Information disclosure in IBM Watson Discovery for IBM Cloud Pak for Data
- Information disclosure in IBM UrbanCode Build
- Information disclosure in IBM UrbanCode Deploy
- Multiple vulnerabilities in IBM UrbanCode Release
- Amazon Linux AMI update for tomcat8
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Amazon Linux AMI update for tomcat9
- HP-UX update for Tomcat
- Multiple vulnerabilities in IBM Control Center
- openEuler 22.03 LTS SP4 update for tomcat
- openEuler 22.03 LTS SP1 update for tomcat
- openEuler 20.03 LTS SP4 update for tomcat
- openEuler 22.03 LTS SP3 update for tomcat
- openEuler 24.03 LTS update for tomcat
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines