QID 730146

Date Published: 2021-07-26

QID 730146: Apache Tomcat Authentication Vulnerability (CVE-2021-30640)

Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm.

Affected Versions:
Apache Tomcat 10.0.0-M1 to 10.0.5
Apache Tomcat 9.0.0.M1 to 9.0.45
Apache Tomcat 8.5.0 to 8.5.65
Apache Tomcat 7.0.0 to 7.0.108

QID Detection Logic (Unauthenticated):
The QID checks for vulnerable version by sending a GET /QUALYS730146 HTTP/1.0 request which helps in retrieving the installed version of Apache Tomcat in the banner of the response.

In limited circumstances it is possible for users to authenticate using variations of their user name and/or to bypass some of the protection provided by the LockOut Realm.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Upgrade to the Apache Tomcat 10.0.6, 9.0.46, 8.5.66, 7.0.109 versions or to the latest version of Apache Tomcat. Please refer to Apache Tomcat Security Advisory.

    CVEs related to QID 730146

    Software Advisories
    Advisory ID Software Component Link
    Apache Tomcat Security Advisory URL Logo tomcat.apache.org/download-10.cgi