CVE-2021-25122

high Apache
CVSS v3 Base Score
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
18.1%
Exploitation probability in 30 days
Top 3% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
None
Availability
None
Published: March 1, 2021 (2016 days ago)
Last Modified: August 25, 2026
Vendor: Apache
Source: NVD

Description

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

CWE

CWE-200

Affected Products

apache tomcatdebian debian linuxoracle agile product lifecycle managementoracle communications cloud native core policyoracle communications cloud native core security edge protection proxyoracle communications instant messaging serveroracle databaseoracle graph server and clientoracle instantis enterprisetrackoracle managed file transfer

References