Vulnerability Name:

CVE-2021-41079 (CCN-209450)

Assigned:2021-09-15
Published:2021-09-15
Updated:2022-10-25
Summary:Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-835
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2021-41079

Source: CCN
Type: Apache Web site
Apache Tomcat

Source: XF
Type: UNKNOWN
apache-cve202141079-dos(209450)

Source: MLIST
Type: Mailing List, Vendor Advisory
[tomcat-users] 20211014 [SECURITY] CVE-2021-42340 Apache Tomcat DoS

Source: MLIST
Type: Mailing List, Vendor Advisory
[tomcat-dev] 20211014 [SECURITY] CVE-2021-42340 Apache Tomcat DoS

Source: MISC
Type: Mailing List, Vendor Advisory
https://lists.apache.org/thread.html/rccdef0349fdf4fb73a4e4403095446d7fe6264e0a58e2df5c6799434%40%3Cannounce.tomcat.apache.org%3E

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20210922 [SECURITY] [DLA 2764-1] tomcat8 security update

Source: CCN
Type: oss-sec Mailing List, Wed, 15 Sep 2021 18:57:33 +0100
CVE-2021-41079: Apache Tomcat DoS with unexpected TLS packet

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20211008-0005/

Source: DEBIAN
Type: Third Party Advisory
DSA-4986

Source: CCN
Type: IBM Security Bulletin 6497499 (Data Risk Manager)
IBM Data Risk Manager is affected by multiple vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6526106 (App Connect Professional)
Multiple vulnerabilities in Apache Tomcat affects App Connect Professional.

Source: CCN
Type: IBM Security Bulletin 6550788 (UrbanCode Release)
IBM UrbanCode Release is affected by CVE-2021-41079

Source: CCN
Type: IBM Security Bulletin 6554912 (UrbanCode Build)
IBM UrbanCode Build is affected by CVE-2021-41079

Source: CCN
Type: IBM Security Bulletin 6568787 (Cloud Pak for Security)
Cloud Pak for Security contains packages that have multiple vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6601977 (Rational Build Forge)
IBM Rational Build Forge is affected by Apache Tomcat version used in it. (CVE-2021-41079)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:apache:tomcat:*:*:*:*:*:*:*:* (Version >= 10.0.0 and <= 10.0.2)
  • OR cpe:/a:apache:tomcat:*:*:*:*:*:*:*:* (Version >= 9.0.0 and < 9.0.44)
  • OR cpe:/a:apache:tomcat:*:*:*:*:*:*:*:* (Version >= 8.5.0 and < 8.5.64)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:11.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:apache:tomcat:10.0.0:m1:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:10.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.0:m1:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:9.0.43:*:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:8.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:apache:tomcat:8.5.63:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:data_risk_manager:2.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:urbancode_build:6.1.4.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8167
    P
    Security update for python-reportlab (Critical)
    2023-06-21
    oval:org.opensuse.security:def:8187
    P
    Security update for the Linux Kernel (Important) (in QA)
    2023-06-15
    oval:org.opensuse.security:def:51977
    P
    Security update for systemd (Important)
    2022-12-28
    oval:org.opensuse.security:def:3544
    P
    libFLAC++6-1.3.0-11.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95174
    P
    tomcat-9.0.36-150200.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:99761
    P
    (Important)
    2022-03-10
    oval:org.opensuse.security:def:100072
    P
    (Critical)
    2022-02-08
    oval:org.opensuse.security:def:113537
    P
    tomcat-9.0.43-2.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:99168
    P
    (Important)
    2021-12-06
    oval:org.opensuse.security:def:111136
    P
    Security update for tomcat (Moderate)
    2021-11-19
    oval:org.opensuse.security:def:8862
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:92413
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:106451
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:69558
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:93986
    P
    (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:100016
    P
    (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:9812
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:96132
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:70503
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:118584
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:105858
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:67319
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:1710
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:76387
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:9057
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:92612
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:106738
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:69753
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:94198
    P
    (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:111787
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:100352
    P
    (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:10172
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:99363
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:92023
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:106053
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:69256
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:102151
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:9418
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:5890
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:92811
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:108817
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:69952
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:94409
    P
    (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:100681
    P
    (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:10363
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:99562
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:8671
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:92218
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:106252
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:69276
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:93772
    P
    (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:102822
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:9613
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:98973
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:6230
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:95438
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:109488
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:70312
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:105663
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:66979
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:102270
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:76047
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:88529
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:33993
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:127186
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:59558
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:23989
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:89213
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:34584
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:59816
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:87501
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:33037
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:125622
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:89471
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:60407
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:88212
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:33735
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:126789
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:58860
    P
    Security update for tomcat (Important)
    2021-11-03
    BACK
    apache tomcat *
    apache tomcat *
    apache tomcat *
    debian debian linux 9.0
    debian debian linux 10.0
    debian debian linux 11.0
    netapp management services for element software and netapp hci -
    apache tomcat 10.0.0 m1
    apache tomcat 10.0.2
    apache tomcat 9.0.0 m1
    apache tomcat 9.0.43
    apache tomcat 8.5.0
    apache tomcat 8.5.63
    ibm data risk manager 2.0.6
    ibm urbancode build 6.1.4.0