CVE-2021-25122
—CVSS 3.1
7.5 high
EPSS
18%p97
Published
()
Modified
Description
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
- Vendors
- apachedebianoracle
- Products
- tomcat, debian linux, agile product lifecycle management, communications cloud native core policy, communications cloud native core security edge protection proxy, communications instant messaging server, database, graph server and client, instantis enterprisetrack, managed file transfer, mysql enterprise monitor, siebel ui framework
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.