Oval Definition:oval:org.opensuse.security:def:202130639
Revision Date:2022-09-02Version:1
Title:CVE-2021-30639
Description:

A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset between requests. This meant that once a non-blocking I/O error occurred, all future requests handled by that request object would fail. Users were able to trigger non-blocking I/O errors, e.g. by dropping a connection, thereby creating the possibility of triggering a DoS. Applications that do not use non-blocking I/O are not exposed to this vulnerability. This issue affects Apache Tomcat 10.0.3 to 10.0.4; 9.0.44; 8.5.64.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-30639
SUSE CVE-2021-30639
Platform(s):SUSE CaaS Platform 4.0
SUSE Enterprise Storage 6
SUSE Linux Enterprise High Performance Computing 12 SP5
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Manager Proxy 4.0
SUSE Manager Retail Branch Server 4.0
SUSE Manager Server 4.0
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • Release Information
  • SUSE CaaS Platform 4.0 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • AND Package Information
  • tomcat is not affected
  • OR tomcat-admin-webapps is not affected
  • OR tomcat-el-3_0-api is not affected
  • OR tomcat-jsp-2_3-api is not affected
  • OR tomcat-lib is not affected
  • OR tomcat-servlet-4_0-api is not affected
  • OR tomcat-webapps is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND tomcat is not affected
  • OR Package Information
  • SUSE Linux Enterprise Server for SAP Applications 12 SP3 is installed
  • AND
  • tomcat is not affected
  • OR tomcat-admin-webapps is not affected
  • OR tomcat-docs-webapp is not affected
  • OR tomcat-el-3_0-api is not affected
  • OR tomcat-javadoc is not affected
  • OR tomcat-jsp-2_3-api is not affected
  • OR tomcat-lib is not affected
  • OR tomcat-servlet-3_1-api is not affected
  • OR tomcat-webapps is not affected
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND
  • tomcat is not affected
  • OR tomcat-admin-webapps is not affected
  • OR tomcat-docs-webapp is not affected
  • OR tomcat-el-3_0-api is not affected
  • OR tomcat-javadoc is not affected
  • OR tomcat-jsp-2_3-api is not affected
  • OR tomcat-lib is not affected
  • OR tomcat-servlet-4_0-api is not affected
  • OR tomcat-webapps is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server for SAP Applications 15 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • AND Package Information
  • tomcat is not affected
  • OR tomcat-admin-webapps is not affected
  • OR tomcat-el-3_0-api is not affected
  • OR tomcat-jsp-2_3-api is not affected
  • OR tomcat-lib is not affected
  • OR tomcat-servlet-4_0-api is not affected
  • OR tomcat-webapps is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND tomcat is not affected
  • OR Package Information
  • SUSE Linux Enterprise Server for SAP Applications 12 SP3 is installed
  • AND
  • tomcat is not affected
  • OR tomcat-admin-webapps is not affected
  • OR tomcat-docs-webapp is not affected
  • OR tomcat-el-3_0-api is not affected
  • OR tomcat-javadoc is not affected
  • OR tomcat-jsp-2_3-api is not affected
  • OR tomcat-lib is not affected
  • OR tomcat-servlet-3_1-api is not affected
  • OR tomcat-webapps is not affected
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND
  • tomcat is not affected
  • OR tomcat-admin-webapps is not affected
  • OR tomcat-docs-webapp is not affected
  • OR tomcat-el-3_0-api is not affected
  • OR tomcat-javadoc is not affected
  • OR tomcat-jsp-2_3-api is not affected
  • OR tomcat-lib is not affected
  • OR tomcat-servlet-4_0-api is not affected
  • OR tomcat-webapps is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Manager Proxy 4.0 is installed
  • OR SUSE Manager Retail Branch Server 4.0 is installed
  • OR SUSE Manager Server 4.0 is installed
  • AND tomcat is not affected
  • OR Package Information
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • AND
  • tomcat is not affected
  • OR tomcat-admin-webapps is not affected
  • OR tomcat-el-3_0-api is not affected
  • OR tomcat-jsp-2_3-api is not affected
  • OR tomcat-lib is not affected
  • OR tomcat-servlet-4_0-api is not affected
  • OR tomcat-webapps is not affected
  • Definition Synopsis
  • Release Information
  • SUSE OpenStack Cloud 8 is installed
  • OR SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • tomcat is not affected
  • OR tomcat-admin-webapps is not affected
  • OR tomcat-docs-webapp is not affected
  • OR tomcat-el-3_0-api is not affected
  • OR tomcat-javadoc is not affected
  • OR tomcat-jsp-2_3-api is not affected
  • OR tomcat-lib is not affected
  • OR tomcat-servlet-3_1-api is not affected
  • OR tomcat-webapps is not affected
  • Definition Synopsis
  • Release Information
  • SUSE OpenStack Cloud 9 is installed
  • OR SUSE OpenStack Cloud Crowbar 9 is installed
  • AND Package Information
  • tomcat is not affected
  • OR tomcat-admin-webapps is not affected
  • OR tomcat-docs-webapp is not affected
  • OR tomcat-el-3_0-api is not affected
  • OR tomcat-javadoc is not affected
  • OR tomcat-jsp-2_3-api is not affected
  • OR tomcat-lib is not affected
  • OR tomcat-servlet-4_0-api is not affected
  • OR tomcat-webapps is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Enterprise Storage 6 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • AND Package Information
  • tomcat is not affected
  • OR tomcat-admin-webapps is not affected
  • OR tomcat-el-3_0-api is not affected
  • OR tomcat-jsp-2_3-api is not affected
  • OR tomcat-lib is not affected
  • OR tomcat-servlet-4_0-api is not affected
  • OR tomcat-webapps is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND tomcat is not affected
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • AND
  • tomcat is not affected
  • OR tomcat-admin-webapps is not affected
  • OR tomcat-docs-webapp is not affected
  • OR tomcat-el-3_0-api is not affected
  • OR tomcat-javadoc is not affected
  • OR tomcat-jsp-2_3-api is not affected
  • OR tomcat-lib is not affected
  • OR tomcat-servlet-4_0-api is not affected
  • OR tomcat-webapps is not affected
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND Package Information
  • tomcat is not affected
  • OR tomcat-admin-webapps is not affected
  • OR tomcat-docs-webapp is not affected
  • OR tomcat-el-3_0-api is not affected
  • OR tomcat-javadoc is not affected
  • OR tomcat-jsp-2_3-api is not affected
  • OR tomcat-lib is not affected
  • OR tomcat-servlet-4_0-api is not affected
  • OR tomcat-webapps is not affected
  • BACK