CVE-2021-25329

high Apache
CVSS v3 Base Score
7.0
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
9.5%
Exploitation probability in 30 days
Top 5% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Published: March 1, 2021 (2016 days ago)
Last Modified: August 25, 2026
Vendor: Apache
Source: NVD

Description

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.

CWE

NVD-CWE-noinfo

Affected Products

apache tomcatdebian debian linuxoracle agile product lifecycle managementoracle communications cloud native core policyoracle communications cloud native core security edge protection proxyoracle communications instant messaging serveroracle databaseoracle graph server and clientoracle instantis enterprisetrackoracle managed file transfer

References