Information disclosure in Apache Tomcat - CVE-2024-21733

 

Information disclosure in Apache Tomcat - CVE-2024-21733

Published: January 19, 2024 / Updated: August 16, 2024


Vulnerability identifier: #VU85619
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21733
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application when processing incomplete HTTP POST requests. A remote attacker can send a specially crafted HTTP POST request to the server and obtain data from a previous request from another user.


Affected software

Apache Tomcat
DataEase
Red Hat Camel for Spring Boot
IBM UrbanCode Release
IBM Rational Build Forge
DevOps
IBM Engineering Requirements Management DOORS Next
Storage Copy Data Management
Storage Virtualize
Ubuntu
openEuler
Fuse
tomcat10 (Ubuntu package)
tomcat-help
tomcat-jsvc
tomcat

How to mitigate CVE-2024-21733

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.64, 9.0.44
DataEase - update to 1.18.24
IBM UrbanCode Release - update to 7.0.0.1
DevOps - update to 7.0.0.1
IBM Rational Build Forge - update to 8.0.0.26
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Storage Copy Data Management - update to 2.2.23.0
Red Hat Camel for Spring Boot - update to 4.4.0
Fuse - update to 7.13.0
Storage Virtualize - addressed in versions 8.4.0.13, 8.5.0.11, 8.6.0.3, 8.6.2.0
tomcat10 (Ubuntu package) - addressed in versions 8.5.39-1ubuntu1~18.04.3+esm5, 9.0.16-3ubuntu0.18.04.2+esm7, 9.0.31-1ubuntu0.9+esm2, 9.0.58-1ubuntu0.2+esm3, 9.0.70-2ubuntu0.1+esm2, 9.0.70-2ubuntu1.24.10.2, 9.0.70-2ubuntu1.25.04.2, 10.1.16-1ubuntu0.1~esm2
tomcat-help - update to 9.0.10-31
tomcat-jsvc - update to 9.0.10-31
tomcat - update to 9.0.10-31

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins