Lucene search

K
kasperskyKaspersky LabKLA19263
HistoryApr 01, 2022 - 12:00 a.m.

KLA19263 OSI vulnerability in Apache Tomcat

2022-04-0100:00:00
Kaspersky Lab
threats.kaspersky.com
22
apache tomcat
vulnerability
information disclosure
malicious users
sensitive information
update
osi
security bypass
affected products
cve-2021-43980

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

4.2

Confidence

High

EPSS

0.002

Percentile

58.5%

Information disclosure vulnerability was found in Apache Tomcat. Malicious users can exploit this vulnerability to obtain sensitive information.

Original advisories

Apache Tomcat 10.x vulnerabilities

Apache Tomcat 9.x vulnerabilities

Apache Tomcat 8.x vulnerabilities

Related products

Apache-Tomcat

CVE list

CVE-2021-43980 warning

Solution

Update to the latest versionTomcat 9.0 Software DownloadsTomcat 8.5 Software Downloads

Tomcat 10.0 Software Downloads

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

Affected Products

  • Apache Tomcat 10.x earlier than 10.0.20Apache Tomcat 9.x earlier than 9.0.62Apache Tomcat 8.x earlier than 8.5.78

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

4.2

Confidence

High

EPSS

0.002

Percentile

58.5%