CVE Vulnerabilities

CVE-2021-25329

Published: Mar 01, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7 LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache7.0.0 (including)7.0.107 (including)
TomcatApache8.5.0 (including)8.5.61 (including)
TomcatApache9.0.0 (including)9.0.41 (including)
TomcatApache9.0.0-milestone1 (including)9.0.0-milestone1 (including)
TomcatApache9.0.0-milestone10 (including)9.0.0-milestone10 (including)
TomcatApache9.0.0-milestone11 (including)9.0.0-milestone11 (including)
TomcatApache9.0.0-milestone12 (including)9.0.0-milestone12 (including)
TomcatApache9.0.0-milestone13 (including)9.0.0-milestone13 (including)
TomcatApache9.0.0-milestone14 (including)9.0.0-milestone14 (including)
TomcatApache9.0.0-milestone15 (including)9.0.0-milestone15 (including)
TomcatApache9.0.0-milestone16 (including)9.0.0-milestone16 (including)
TomcatApache9.0.0-milestone17 (including)9.0.0-milestone17 (including)
TomcatApache9.0.0-milestone18 (including)9.0.0-milestone18 (including)
TomcatApache9.0.0-milestone19 (including)9.0.0-milestone19 (including)
TomcatApache9.0.0-milestone2 (including)9.0.0-milestone2 (including)
TomcatApache9.0.0-milestone20 (including)9.0.0-milestone20 (including)
TomcatApache9.0.0-milestone21 (including)9.0.0-milestone21 (including)
TomcatApache9.0.0-milestone22 (including)9.0.0-milestone22 (including)
TomcatApache9.0.0-milestone23 (including)9.0.0-milestone23 (including)
TomcatApache9.0.0-milestone24 (including)9.0.0-milestone24 (including)
TomcatApache9.0.0-milestone25 (including)9.0.0-milestone25 (including)
TomcatApache9.0.0-milestone26 (including)9.0.0-milestone26 (including)
TomcatApache9.0.0-milestone27 (including)9.0.0-milestone27 (including)
TomcatApache9.0.0-milestone3 (including)9.0.0-milestone3 (including)
TomcatApache9.0.0-milestone4 (including)9.0.0-milestone4 (including)
TomcatApache9.0.0-milestone5 (including)9.0.0-milestone5 (including)
TomcatApache9.0.0-milestone6 (including)9.0.0-milestone6 (including)
TomcatApache9.0.0-milestone7 (including)9.0.0-milestone7 (including)
TomcatApache9.0.0-milestone8 (including)9.0.0-milestone8 (including)
TomcatApache9.0.0-milestone9 (including)9.0.0-milestone9 (including)
TomcatApache10.0.0 (including)10.0.0 (including)
TomcatApache10.0.0-milestone1 (including)10.0.0-milestone1 (including)
TomcatApache10.0.0-milestone10 (including)10.0.0-milestone10 (including)
TomcatApache10.0.0-milestone2 (including)10.0.0-milestone2 (including)
TomcatApache10.0.0-milestone3 (including)10.0.0-milestone3 (including)
TomcatApache10.0.0-milestone4 (including)10.0.0-milestone4 (including)
TomcatApache10.0.0-milestone5 (including)10.0.0-milestone5 (including)
TomcatApache10.0.0-milestone6 (including)10.0.0-milestone6 (including)
TomcatApache10.0.0-milestone7 (including)10.0.0-milestone7 (including)
TomcatApache10.0.0-milestone8 (including)10.0.0-milestone8 (including)
TomcatApache10.0.0-milestone9 (including)10.0.0-milestone9 (including)
Red Hat Fuse 7.11RedHattomcat*
Red Hat JBoss Web Server 5RedHattomcat*
Red Hat JBoss Web Server 5.5 on RHEL 7RedHatjws5-ecj-0:4.12.0-3.redhat_2.2.el7jws*
Red Hat JBoss Web Server 5.5 on RHEL 7RedHatjws5-mod_cluster-0:1.4.3-2.Final_redhat_00002.1.el7jws*
Red Hat JBoss Web Server 5.5 on RHEL 7RedHatjws5-tomcat-0:9.0.43-11.redhat_00011.1.el7jws*
Red Hat JBoss Web Server 5.5 on RHEL 7RedHatjws5-tomcat-native-0:1.2.26-3.redhat_3.el7jws*
Red Hat JBoss Web Server 5.5 on RHEL 7RedHatjws5-tomcat-vault-0:1.1.8-2.Final_redhat_00003.1.el7jws*
Red Hat JBoss Web Server 5.5 on RHEL 8RedHatjws5-ecj-0:4.12.0-3.redhat_2.2.el8jws*
Red Hat JBoss Web Server 5.5 on RHEL 8RedHatjws5-mod_cluster-0:1.4.3-2.Final_redhat_00002.1.el8jws*
Red Hat JBoss Web Server 5.5 on RHEL 8RedHatjws5-tomcat-0:9.0.43-11.redhat_00011.1.el8jws*
Red Hat JBoss Web Server 5.5 on RHEL 8RedHatjws5-tomcat-native-0:1.2.26-3.redhat_3.el8jws*
Red Hat JBoss Web Server 5.5 on RHEL 8RedHatjws5-tomcat-vault-0:1.1.8-2.Final_redhat_00003.1.el8jws*
Red Hat support for Spring Boot 2.3.10RedHattomcat*
Tomcat6Ubuntuesm-apps/xenial*
Tomcat6Ubuntuesm-infra-legacy/trusty*
Tomcat6Ubuntuprecise/esm*
Tomcat6Ubuntutrusty*
Tomcat6Ubuntutrusty/esm*
Tomcat6Ubuntuupstream*
Tomcat6Ubuntuxenial*
Tomcat7Ubuntubionic*
Tomcat7Ubuntuesm-apps/bionic*
Tomcat7Ubuntuesm-apps/xenial*
Tomcat7Ubuntuesm-infra-legacy/trusty*
Tomcat7Ubuntutrusty*
Tomcat7Ubuntutrusty/esm*
Tomcat7Ubuntuupstream*
Tomcat7Ubuntuxenial*
Tomcat8Ubuntubionic*
Tomcat8Ubuntuesm-apps/bionic*
Tomcat8Ubuntuesm-infra/xenial*
Tomcat8Ubuntuxenial*
Tomcat9Ubuntubionic*
Tomcat9Ubuntuesm-apps/bionic*
Tomcat9Ubuntuesm-apps/focal*
Tomcat9Ubuntufocal*
Tomcat9Ubuntugroovy*
Tomcat9Ubuntuhirsute*
Tomcat9Ubuntuimpish*
Tomcat9Ubuntukinetic*
Tomcat9Ubuntulunar*
Tomcat9Ubuntumantic*
Tomcat9Ubuntuoracular*
Tomcat9Ubuntuupstream*

References