CVE-2021-30640

Description

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
EPSS Score
Exploitation Probability
0.123

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-30640 are fixed in 12 May 2021 Fixed in Apache Tomcat 10.0.6Windows
Vulnerabilities CVE-2021-30640 are fixed in 12 May 2021 Fixed in Apache Tomcat 9.0.46Windows
Vulnerabilities CVE-2021-30640 are fixed in 12 May 2021 Fixed in Apache Tomcat 8.5.66Windows
Vulnerabilities CVE-2021-30640 are fixed in 26 April 2021 Fixed in Apache Tomcat 7.0.109Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 10.15Windows
Vulnerabilities CVE-2021-30640,CVE-2021-30639 are fixed in Apache - tomcat 10.0.5Windows
Vulnerabilities CVE-2021-30640,CVE-2021-30639 are fixed in Apache - tomcat 9.0.45Windows
Vulnerabilities CVE-2021-30640,CVE-2021-30639 are fixed in Apache - tomcat 8.5.65Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 10.11Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 11.1Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.0Windows
tomcat9 security update(DSA-4952-1) tomcat9_9.0.31-1~deb10u5_all.debLinux
SUSE-SU-2021:3602-1(SUSE Linux Enterprise Server 12-SP5 ) javapackages-tools-2.0.1-13.1.x86_64.rpmLinux
SUSE-SU-2021:3602-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-9.0.36-3.71.1.noarch.rpmLinux
SUSE-SU-2021:3602-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-admin-webapps-9.0.36-3.71.1.noarch.rpmLinux
SUSE-SU-2021:3602-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-docs-webapp-9.0.36-3.71.1.noarch.rpmLinux
SUSE-SU-2021:3602-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-el-3_0-api-9.0.36-3.71.1.noarch.rpmLinux
SUSE-SU-2021:3602-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-javadoc-9.0.36-3.71.1.noarch.rpmLinux
SUSE-SU-2021:3602-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-jsp-2_3-api-9.0.36-3.71.1.noarch.rpmLinux
SUSE-SU-2021:3602-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-lib-9.0.36-3.71.1.noarch.rpmLinux
SUSE-SU-2021:3602-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-servlet-4_0-api-9.0.36-3.71.1.noarch.rpmLinux
SUSE-SU-2021:3602-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-webapps-9.0.36-3.71.1.noarch.rpmLinux
Apache Tomcat 9 - Servlet and JSP engine (USN-5360-1) tomcat9_9.0.31-1ubuntu0.2_all.debLinux
Apache Tomcat 9 - Servlet and JSP engine (USN-5360-1) tomcat9_9.0.16-3ubuntu0.18.04.2_all.debLinux
Apache Tomcat 9 - Servlet and JSP engine (USN-5360-1) tomcat9-common_9.0.31-1ubuntu0.2_all.debLinux
Apache Tomcat 9 - Servlet and JSP engine (USN-5360-1) tomcat9-common_9.0.16-3ubuntu0.18.04.2_all.debLinux
Apache Tomcat 9 - Servlet and JSP engine (USN-5360-1) libtomcat9-java_9.0.31-1ubuntu0.2_all.debLinux
Apache Tomcat 9 - Servlet and JSP engine (USN-5360-1) libtomcat9-java_9.0.16-3ubuntu0.18.04.2_all.debLinux
Apache Tomcat 9 - Servlet and JSP engine (USN-5360-1) libtomcat9-embed-java_9.0.31-1ubuntu0.2_all.debLinux
Apache Tomcat 9 - Servlet and JSP engine (USN-5360-1) libtomcat9-embed-java_9.0.16-3ubuntu0.18.04.2_all.debLinux
Vulnerabilities CVE-2021-30640 are fixed in 12 May 2021 Fixed in Apache Tomcat 10.0.6 (For Linux)Linux
Vulnerabilities CVE-2021-30640 are fixed in 12 May 2021 Fixed in Apache Tomcat 9.0.46 (For Linux)Linux
Vulnerabilities CVE-2021-30640 are fixed in 12 May 2021 Fixed in Apache Tomcat 8.5.66 (For Linux)Linux
Vulnerabilities CVE-2021-30640 are fixed in 26 April 2021 Fixed in Apache Tomcat 7.0.109 (For Linux)Linux
Vulnerabilities CVE-2021-30640,CVE-2021-30639 are fixed in Apache - tomcat for Linux 10.0.5Linux
Vulnerabilities CVE-2021-30640,CVE-2021-30639 are fixed in Apache - tomcat for Linux 9.0.45Linux
Vulnerabilities CVE-2021-30640,CVE-2021-30639 are fixed in Apache - tomcat for Linux 8.5.65Linux
Improper Encoding or Escaping of Output Vulnerability (CVE-2021-30640)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234