Vulnerability Name:

CVE-2021-25122 (CCN-197517)

Assigned:2021-03-01
Published:2021-03-01
Updated:2022-10-25
Summary:When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2021-25122

Source: CCN
Type: Apache Web site
Apache Tomcat

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20210301 CVE-2021-25122: Apache Tomcat h2c request mix-up

Source: XF
Type: UNKNOWN
apache-cve202125122-info-disc(197517)

Source: CCN
Type: Apache Mailing List, 2021/03/01 11:04:57
[SECURITY] CVE-2021-25122 Apache Tomcat h2c request mix-up

Source: CONFIRM
Type: Mailing List, Vendor Advisory
N/A

Source: MLIST
Type: Mailing List, Vendor Advisory
[announce] 20210301 [SECURITY] CVE-2021-25122 Apache Tomcat h2c request mix-up

Source: MLIST
Type: Mailing List, Vendor Advisory
[tomcat-announce] 20210301 [SECURITY] CVE-2021-25122 Apache Tomcat h2c request mix-up

Source: MLIST
Type: Mailing List, Vendor Advisory
[tomcat-dev] 20210301 [SECURITY] CVE-2021-25122 Apache Tomcat h2c request mix-up

Source: MLIST
Type: Mailing List, Vendor Advisory
[tomcat-users] 20210301 [SECURITY] CVE-2021-25122 Apache Tomcat h2c request mix-up

Source: MLIST
Type: Mailing List, Vendor Advisory
[tomcat-users] 20210305 RE: [SECURITY] CVE-2021-25122 Apache Tomcat h2c request mix-up

Source: MLIST
Type: Mailing List, Vendor Advisory
[tomcat-users] 20210305 Re: [SECURITY] CVE-2021-25122 Apache Tomcat h2c request mix-up

Source: MLIST
Type: Mailing List, Patch, Vendor Advisory
[tomcat-dev] 20210301 svn commit: r1887027 - in /tomcat/site/trunk: docs/security-10.html docs/security-7.html docs/security-8.html docs/security-9.html xdocs/security-10.xml xdocs/security-7.xml xdocs/security-8.xml xdocs/security-9.xml

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20210316 [SECURITY] [DLA 2596-1] tomcat8 security update

Source: CCN
Type: oss-sec Mailing List, Mon, 1 Mar 2021 11:13:18 +0000
CVE-2021-25122: Apache Tomcat h2c request mix-up

Source: GENTOO
Type: Third Party Advisory
GLSA-202208-34

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20210409-0002/

Source: DEBIAN
Type: Third Party Advisory
DSA-4891

Source: CCN
Type: IBM Security Bulletin 6440543 (App Connect Professional)
App Connect Professional is affected by Apache Tomcat vulnerabilities.

Source: CCN
Type: IBM Security Bulletin 6442857 (Tivoli Application Dependency Discovery Manager)
Open Source Apache Tomcat vulnerabilities affect IBM Tivoli Application Dependency Discovery Manager (CVE-2021-25122, CVE-2021-25329)

Source: CCN
Type: IBM Security Bulletin 6449972 (Data Risk Manager)
IBM Data Risk Manager is affected by multiple vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6475673 (QRadar SIEM)
IBM QRadar SIEM is vulnerable to Using Components with Known Vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6550784 (UrbanCode Release)
IBM UrbanCode Release is affected by CVE-2021-25122 and CVE-2021-25329

Source: CCN
Type: IBM Security Bulletin 6554916 (UrbanCode Build)
IBM UrbanCode Build is affected by CVE-2021-25122 and CVE-2021-25329

Source: CCN
Type: IBM Security Bulletin 6568787 (Cloud Pak for Security)
Cloud Pak for Security contains packages that have multiple vulnerabilities

Source: N/A
Type: Patch, Third Party Advisory
N/A

Source: CCN
Type: Oracle CPUJan2022
Oracle Critical Patch Update Advisory - January 2022

Source: MISC
Type: Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html

Source: CCN
Type: Oracle CPUJul2021
Oracle Critical Patch Update Advisory - July 2021

Source: CCN
Type: Oracle CPUOct2021
Oracle Critical Patch Update Advisory - October 2021

Source: MISC
Type: Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html

Vulnerable Configuration:Configuration 1:
  • cpe:/a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone12:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone13:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone14:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone15:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone16:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone17:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone18:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone19:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone2:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone20:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone21:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone22:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone23:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone24:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone25:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone26:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone27:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone3:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone4:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:milestone5:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.0:milestone3:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.0:milestone4:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.0:milestone2:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.0:milestone1:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.0:milestone5:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.0:milestone6:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.0:milestone7:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.0:milestone8:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.0:milestone9:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:*:*:*:*:*:*:*:* (Version >= 9.0.0 and <= 9.0.41)
  • OR cpe:/a:apache:tomcat:*:*:*:*:*:*:*:* (Version >= 8.5.0 and <= 8.5.61)
  • OR cpe:/a:apache:tomcat:10.0.0:milestone10:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.0:-:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:oracle:managed_file_transfer:12.2.1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:database:12.2.0.1:*:*:*:enterprise:*:*:*
  • OR cpe:/a:oracle:database:19c:*:*:*:enterprise:*:*:*
  • OR cpe:/a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:* (Version <= 21.9)
  • OR cpe:/a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* (Version <= 8.0.23)
  • OR cpe:/a:oracle:graph_server_and_client:*:*:*:*:*:*:*:* (Version < 21.3.0)
  • OR cpe:/a:oracle:graph_server_and_client:21.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:database:21c:*:*:*:enterprise:*:*:*
  • OR cpe:/a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:communications_instant_messaging_server:10.0.1.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.6.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:apache:tomcat:8.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:m1:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.0:m1:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:8.5.61:*:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.41:*:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.0:-:*:*:*:*:*:*
  • AND
  • cpe:/a:oracle:database_server:12.2.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:app_connect:7.5.3.0:*:*:*:professional:*:*:*
  • OR cpe:/a:oracle:database_server:19c:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_application_dependency_discovery_manager:7.3.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:data_risk_manager:2.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.4.0:-:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.4.3:-:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.3.3:p8:*:*:*:*:*:*
  • OR cpe:/a:ibm:urbancode_build:6.1.4.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8153
    P
    Security update for php7 (Moderate) (in QA)
    2023-06-15
    oval:org.opensuse.security:def:643
    P
    Security update for python-paramiko (Important) (in QA)
    2022-09-30
    oval:org.opensuse.security:def:3544
    P
    libFLAC++6-1.3.0-11.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95174
    P
    tomcat-9.0.36-150200.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95179
    P
    PackageKit-gstreamer-plugin-1.2.4-150400.1.11 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:101892
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:113536
    P
    tomcat-9.0.36-8.4 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:99432
    P
    (Important)
    2021-11-11
    oval:org.opensuse.security:def:106932
    P
    tomcat-9.0.36-8.4 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:96785
    P
    tboot-20170711_1.9.8-8.32 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96786
    P
    tcpdump-4.9.2-3.3.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:101419
    P
    tomcat-9.0.36-3.24.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2329
    P
    tomcat-9.0.36-3.24.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63418
    P
    tomcat-9.0.36-3.24.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:99631
    P
    (Important)
    2021-04-30
    oval:org.opensuse.security:def:99936
    P
    (Low)
    2021-04-28
    oval:org.opensuse.security:def:111299
    P
    Security update for tomcat (Important)
    2021-04-02
    oval:org.opensuse.security:def:109474
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:92482
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:69623
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:93730
    P
    (Important)
    2021-04-01
    oval:org.opensuse.security:def:102808
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:98843
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:93186
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:91893
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:66720
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:10233
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:92681
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:69822
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:93945
    P
    (Important)
    2021-04-01
    oval:org.opensuse.security:def:99930
    P
    (Important)
    2021-04-01
    oval:org.opensuse.security:def:9483
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:99038
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:92088
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:69242
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:75788
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:8732
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:92880
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:94156
    P
    (Important)
    2021-04-01
    oval:org.opensuse.security:def:100265
    P
    (Important)
    2021-04-01
    oval:org.opensuse.security:def:9682
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:99233
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:5631
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:96118
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:108558
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:92283
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:118570
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:8927
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:93033
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:70373
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:94368
    P
    (Important)
    2021-04-01
    oval:org.opensuse.security:def:100595
    P
    (Important)
    2021-04-01
    oval:org.opensuse.security:def:10229
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:88270
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:125677
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:59612
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:9475
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:34666
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:8725
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:88587
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:24044
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:126843
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:59870
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:5988
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:89267
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:33789
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:127240
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:97355
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:70369
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:60489
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:69615
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:52032
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:89525
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:34047
    P
    Security update for tomcat (Important)
    2021-03-30
    BACK
    apache tomcat 9.0.0 milestone1
    apache tomcat 9.0.0 milestone10
    apache tomcat 9.0.0 milestone11
    apache tomcat 9.0.0 milestone12
    apache tomcat 9.0.0 milestone13
    apache tomcat 9.0.0 milestone14
    apache tomcat 9.0.0 milestone15
    apache tomcat 9.0.0 milestone16
    apache tomcat 9.0.0 milestone17
    apache tomcat 9.0.0 milestone18
    apache tomcat 9.0.0 milestone19
    apache tomcat 9.0.0 milestone2
    apache tomcat 9.0.0 milestone20
    apache tomcat 9.0.0 milestone21
    apache tomcat 9.0.0 milestone22
    apache tomcat 9.0.0 milestone23
    apache tomcat 9.0.0 milestone24
    apache tomcat 9.0.0 milestone25
    apache tomcat 9.0.0 milestone26
    apache tomcat 9.0.0 milestone27
    apache tomcat 9.0.0 milestone3
    apache tomcat 9.0.0 milestone4
    apache tomcat 9.0.0 milestone5
    apache tomcat 10.0.0 milestone3
    apache tomcat 10.0.0 milestone4
    apache tomcat 10.0.0 milestone2
    apache tomcat 10.0.0 milestone1
    apache tomcat 10.0.0 milestone5
    apache tomcat 10.0.0 milestone6
    apache tomcat 10.0.0 milestone7
    apache tomcat 10.0.0 milestone8
    apache tomcat 10.0.0 milestone9
    apache tomcat *
    apache tomcat *
    apache tomcat 10.0.0 milestone10
    apache tomcat 10.0.0 -
    debian debian linux 9.0
    debian debian linux 10.0
    oracle managed file transfer 12.2.1.3.0
    oracle instantis enterprisetrack 17.1
    oracle instantis enterprisetrack 17.2
    oracle instantis enterprisetrack 17.3
    oracle agile plm 9.3.3
    oracle agile plm 9.3.6
    oracle database 12.2.0.1
    oracle database 19c
    oracle managed file transfer 12.2.1.4.0
    oracle siebel ui framework *
    oracle mysql enterprise monitor *
    oracle graph server and client *
    oracle graph server and client 21.3.0
    oracle database 21c
    oracle communications cloud native core policy 1.14.0
    oracle communications instant messaging server 10.0.1.5.0
    oracle communications cloud native core security edge protection proxy 1.6.0
    apache tomcat 8.5.0
    apache tomcat 9.0.0 m1
    apache tomcat 10.0.0 m1
    apache tomcat 8.5.61
    apache tomcat 9.0.41
    apache tomcat 10.0.0 -
    oracle database server 12.2.0.1
    oracle instantis enterprisetrack 17.1
    oracle instantis enterprisetrack 17.2
    oracle instantis enterprisetrack 17.3
    ibm qradar security information and event manager 7.3.0
    ibm app connect 7.5.3.0
    oracle database server 19c
    ibm tivoli application dependency discovery manager 7.3.0.0
    ibm data risk manager 2.0.6
    ibm qradar security information and event manager 7.4.0
    ibm qradar security information and event manager 7.4.3 -
    ibm qradar security information and event manager 7.3.3 p8
    ibm urbancode build 6.1.4.0