QID 150366
Date Published: 2021-08-09
QID 150366: Apache Tomcat Authentication Vulnerability (CVE-2021-30640)
Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm.
Affected Versions:
Apache Tomcat 10.0.0-M1 to 10.0.5
Apache Tomcat 9.0.0.M1 to 9.0.45
Apache Tomcat 8.5.0 to 8.5.65
Apache Tomcat 7.0.0 to 7.0.108
QID Detection Logic (Unauthenticated):
The QID checks for vulnerable version by sending a GET /QUALYSTESTRANDOM.1tmhl HTTP/1.0 request which helps in retrieving the installed version of Apache Tomcat in the banner of the response.
In limited circumstances it is possible for users to authenticate using variations of their user name and/or to bypass some of the protection provided by the LockOut Realm.
- Apache Tomcat 10.0.6 -
tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.0.6
CVEs related to QID 150366
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Tomcat Security Advisory |
|