ZeroHour

CVE-2021-25122

CVSS 3.1
7.5 high
EPSS
18%p97
Published
()
Modified
Description

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

Vendors
apachedebianoracle
Products
tomcat, debian linux, agile product lifecycle management, communications cloud native core policy, communications cloud native core security edge protection proxy, communications instant messaging server, database, graph server and client, instantis enterprisetrack, managed file transfer, mysql enterprise monitor, siebel ui framework
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.