HIGH · 7.5

CVE-2021-25122

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body ...

Vulnerability Description

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ApacheTomcat>= 8.5.0, <= 8.5.61
DebianDebian Linux9.0
OracleAgile Plm9.3.3
OracleCommunications Cloud Native Core Policy1.14.0
OracleCommunications Cloud Native Core Security Edge Protection Proxy1.6.0
OracleCommunications Instant Messaging Server10.0.1.5.0
OracleDatabase12.2.0.1
OracleGraph Server And Client< 21.3.0
OracleInstantis Enterprisetrack17.1
OracleManaged File Transfer12.2.1.3.0
OracleMysql Enterprise Monitor<= 8.0.23
OracleSiebel Ui Framework<= 21.9

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-25122?

CVE-2021-25122 is a vulnerability with a CVSS score of 7.5 (HIGH). When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body ...

How severe is CVE-2021-25122?

CVE-2021-25122 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-25122?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Debian Debian Linux, Oracle Agile Plm, Oracle Communications Cloud Native Core Policy, Oracle Communications Cloud Native Core Security Edge Protection Proxy.