CVE-2021-30640
Summary
| CVE | CVE-2021-30640 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-12 15:15:00 UTC |
| Updated | 2022-10-27 01:08:00 UTC |
| Description | A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| July 2021 Apache Tomcat Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| Oracle Critical Patch Update Advisory - July 2021 |
N/A |
www.oracle.com |
Third Party Advisory |
| Oracle Critical Patch Update Advisory - October 2021 |
MISC |
www.oracle.com |
|
| Debian -- Security Information -- DSA-4986-1 tomcat9 |
DEBIAN |
www.debian.org |
|
| [SECURITY] [DLA 2733-1] tomcat8 security update |
MLIST |
lists.debian.org |
|
| Oracle Critical Patch Update Advisory - January 2022 |
MISC |
www.oracle.com |
|
| Pony Mail! |
MISC |
lists.apache.org |
|
| Debian -- Security Information -- DSA-4952-1 tomcat9 |
DEBIAN |
www.debian.org |
|
| Apache Tomcat: Multiple Vulnerabilities (GLSA 202208-34) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150366 Apache Tomcat Authentication Vulnerability (CVE-2021-30640)
- 178743 Debian Security Update for tomcat8 (DLA 2733-1)
- 178746 Debian Security Update for tomcat9 (DSA 4952-1)
- 179833 Debian Security Update for tomcat9 (CVE-2021-30640)
- 198724 Ubuntu Security Notification for Tomcat Vulnerabilities (USN-5360-1)
- 239916 Red Hat Update for red hat jboss web server 5.6.0 (RHSA-2021:4861)
- 296065 Oracle Solaris 11.4 Support Repository Update (SRU) 39.107.1 Missing (CPUOCT2021)
- 352801 Amazon Linux Security Advisory for tomcat7: ALAS-2021-1534
- 356267 Amazon Linux Security Advisory for tomcat : ALASTOMCAT8.5-2023-007
- 670731 EulerOS Security Update for tomcat (EulerOS-SA-2021-2489)
- 670762 EulerOS Security Update for tomcat (EulerOS-SA-2021-2520)
- 670984 EulerOS Security Update for tomcat (EulerOS-SA-2021-2619)
- 690074 Free Berkeley Software Distribution (FreeBSD) Security Update for tomcat (8b571fb2-f311-11eb-b12b-fc4dd43e2b6a)
- 710609 Gentoo Linux Apache Tomcat Multiple Vulnerabilities (GLSA 202208-34)
- 730146 Apache Tomcat Authentication Vulnerability (CVE-2021-30640)
- 730206 McAfee Web Gateway Multiple Vulnerabilities (WP-3792, WP-4003, WP-4021, WP-4058, WP-4067)
- 751320 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2021:3602-1)
- 751355 OpenSUSE Security Update for tomcat (openSUSE-SU-2021:3672-1)
- 751364 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2021:3669-1)
- 751365 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2021:3670-1)
- 751370 OpenSUSE Security Update for tomcat (openSUSE-SU-2021:1490-1)
- 980361 Java (maven) Security Update for org.apache.tomcat:tomcat (GHSA-36qh-35cm-5w2w)