CVE-2021-30640 is a medium-severity vulnerability affecting Apache Tomcat versions 10.0.0-M1 to 10.0.5, 9.0.0.M1 to 9.0.45, and 8.5.0 to 8.5.65, as well as products from Debian and Oracle. This flaw in the JNDI Realm allows attackers to authenticate with variations of valid usernames or bypass LockOut Realm protections. With a CVSS score of 6.5, this network-based attack has high complexity but requires no user interaction, potentially leading to low confidentiality and high integrity impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, < 7.0.109CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 8.5.0, < 8.5.66CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.46CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.0.6CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
1.14.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.