Lucene search

K
f5F5F5:K35033051
HistoryJul 28, 2021 - 12:00 a.m.

K35033051 : Tomcat vulnerability CVE-2021-30640

2021-07-2800:00:00
my.f5.com
118
apache tomcat
jndi realm
cve-2021-30640
authentication
lockout realm

AI Score

6.4

Confidence

High

EPSS

0.002

Percentile

58.4%

Security Advisory Description

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65. (CVE-2021-30640)

Impact

An attacker may be able to authenticate using variations of a valid username and bypass some of the protection provided by the LockOut Realm.