CVE-2021-41079

Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
Affected Products (NVD)
VendorProductVersion
apachetomcat
8.5.0 ≤
𝑥
< 8.5.64
apachetomcat
9.0.0 ≤
𝑥
< 9.0.44
apachetomcat
10.0.0 ≤
𝑥
≤ 10.0.2
debiandebian_linux
9.0
debiandebian_linux
10.0
debiandebian_linux
11.0
netappmanagement_services_for_element_software_and_netapp_hci
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tomcat9
bookworm
9.0.70-2
fixed
bullseye
9.0.43-2~deb11u10
fixed
bullseye (security)
9.0.43-2~deb11u10
fixed
sid
9.0.95-1
fixed
trixie
9.0.95-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tomcat6
bionic
dne
focal
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
not-affected
xenial
not-affected
tomcat7
bionic
not-affected
focal
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
not-affected
xenial
not-affected
tomcat8
bionic
Fixed 8.5.39-1ubuntu1~18.04.3+esm2
released
focal
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
not-affected
tomcat9
bionic
Fixed 9.0.16-3ubuntu0.18.04.2
released
focal
Fixed 9.0.31-1ubuntu0.2
released
hirsute
ignored
impish
ignored
jammy
not-affected
kinetic
ignored
lunar
ignored
mantic
ignored
noble
not-affected
trusty
dne
xenial
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
javapackages-tools
suse enterprise sap 12 SP5
2.0.1-13.1
fixed
suse enterprise server 12 SP4
2.0.1-13.1
fixed
suse enterprise server 12 SP5
2.0.1-13.1
fixed
tomcat
suse enterprise sap 12 SP5
9.0.36-3.71.1
fixed
suse enterprise sap 15
9.0.36-3.84.1
fixed
suse enterprise sap 15 SP1
9.0.36-4.63.1
fixed
suse enterprise sap 15 SP2
9.0.36-13.1
fixed
suse enterprise sap 15 SP3
9.0.36-13.1
fixed
suse enterprise sap 15 SP4
9.0.36-13.1
fixed
suse enterprise sap 15 SP5
9.0.36-13.1
fixed
suse enterprise sap 15 SP6
9.0.36-13.1
fixed
suse enterprise sap 15 SP7
9.0.36-13.1
fixed
suse enterprise server 12 SP4
9.0.36-3.71.1
fixed
suse enterprise server 12 SP5
9.0.115-3.160.1
fixed
suse enterprise server 15
9.0.36-3.84.1
fixed
suse enterprise server 15 SP1
9.0.36-4.63.1
fixed
suse enterprise server 15 SP2
9.0.36-13.1
fixed
suse enterprise server 15 SP3
9.0.36-13.1
fixed
suse enterprise server 15 SP4
9.0.36-13.1
fixed
suse enterprise server 15 SP5
9.0.36-13.1
fixed
suse enterprise server 15 SP6
9.0.36-13.1
fixed
suse enterprise server 15 SP7
9.0.36-13.1
fixed
tomcat-admin-webapps
suse enterprise sap 12 SP5
9.0.36-3.71.1
fixed
suse enterprise sap 15
9.0.36-3.84.1
fixed
suse enterprise sap 15 SP1
9.0.36-4.63.1
fixed
suse enterprise sap 15 SP2
9.0.36-13.1
fixed
suse enterprise sap 15 SP3
9.0.36-13.1
fixed
suse enterprise sap 15 SP4
9.0.36-13.1
fixed
suse enterprise sap 15 SP5
9.0.36-13.1
fixed
suse enterprise sap 15 SP6
9.0.36-13.1
fixed
suse enterprise sap 15 SP7
9.0.36-13.1
fixed
suse enterprise server 12 SP4
9.0.36-3.71.1
fixed
suse enterprise server 12 SP5
9.0.115-3.160.1
fixed
suse enterprise server 15
9.0.36-3.84.1
fixed
suse enterprise server 15 SP1
9.0.36-4.63.1
fixed
suse enterprise server 15 SP2
9.0.36-13.1
fixed
suse enterprise server 15 SP3
9.0.36-13.1
fixed
suse enterprise server 15 SP4
9.0.36-13.1
fixed
suse enterprise server 15 SP5
9.0.36-13.1
fixed
suse enterprise server 15 SP6
9.0.36-13.1
fixed
suse enterprise server 15 SP7
9.0.36-13.1
fixed
tomcat-docs-webapp
suse enterprise sap 12 SP5
9.0.36-3.71.1
fixed
suse enterprise server 12 SP4
9.0.36-3.71.1
fixed
suse enterprise server 12 SP5
9.0.115-3.160.1
fixed
tomcat-el-3_0-api
suse enterprise sap 12 SP5
9.0.36-3.71.1
fixed
suse enterprise sap 15
9.0.36-3.84.1
fixed
suse enterprise sap 15 SP1
9.0.36-4.63.1
fixed
suse enterprise sap 15 SP2
9.0.36-13.1
fixed
suse enterprise sap 15 SP3
9.0.36-13.1
fixed
suse enterprise sap 15 SP4
9.0.36-13.1
fixed
suse enterprise sap 15 SP5
9.0.36-13.1
fixed
suse enterprise sap 15 SP6
9.0.36-13.1
fixed
suse enterprise sap 15 SP7
9.0.36-13.1
fixed
suse enterprise server 12 SP4
9.0.36-3.71.1
fixed
suse enterprise server 12 SP5
9.0.115-3.160.1
fixed
suse enterprise server 15
9.0.36-3.84.1
fixed
suse enterprise server 15 SP1
9.0.36-4.63.1
fixed
suse enterprise server 15 SP2
9.0.36-13.1
fixed
suse enterprise server 15 SP3
9.0.36-13.1
fixed
suse enterprise server 15 SP4
9.0.36-13.1
fixed
suse enterprise server 15 SP5
9.0.36-13.1
fixed
suse enterprise server 15 SP6
9.0.36-13.1
fixed
suse enterprise server 15 SP7
9.0.36-13.1
fixed
tomcat-javadoc
suse enterprise sap 12 SP5
9.0.36-3.71.1
fixed
suse enterprise server 12 SP4
9.0.36-3.71.1
fixed
suse enterprise server 12 SP5
9.0.115-3.160.1
fixed
tomcat-jsp-2_3-api
suse enterprise sap 12 SP5
9.0.36-3.71.1
fixed
suse enterprise sap 15
9.0.36-3.84.1
fixed
suse enterprise sap 15 SP1
9.0.36-4.63.1
fixed
suse enterprise sap 15 SP2
9.0.36-13.1
fixed
suse enterprise sap 15 SP3
9.0.36-13.1
fixed
suse enterprise sap 15 SP4
9.0.36-13.1
fixed
suse enterprise sap 15 SP5
9.0.36-13.1
fixed
suse enterprise sap 15 SP6
9.0.36-13.1
fixed
suse enterprise sap 15 SP7
9.0.36-13.1
fixed
suse enterprise server 12 SP4
9.0.36-3.71.1
fixed
suse enterprise server 12 SP5
9.0.115-3.160.1
fixed
suse enterprise server 15
9.0.36-3.84.1
fixed
suse enterprise server 15 SP1
9.0.36-4.63.1
fixed
suse enterprise server 15 SP2
9.0.36-13.1
fixed
suse enterprise server 15 SP3
9.0.36-13.1
fixed
suse enterprise server 15 SP4
9.0.36-13.1
fixed
suse enterprise server 15 SP5
9.0.36-13.1
fixed
suse enterprise server 15 SP6
9.0.36-13.1
fixed
suse enterprise server 15 SP7
9.0.36-13.1
fixed
tomcat-lib
suse enterprise sap 12 SP5
9.0.36-3.71.1
fixed
suse enterprise sap 15
9.0.36-3.84.1
fixed
suse enterprise sap 15 SP1
9.0.36-4.63.1
fixed
suse enterprise sap 15 SP2
9.0.36-13.1
fixed
suse enterprise sap 15 SP3
9.0.36-13.1
fixed
suse enterprise sap 15 SP4
9.0.36-13.1
fixed
suse enterprise sap 15 SP5
9.0.36-13.1
fixed
suse enterprise sap 15 SP6
9.0.36-13.1
fixed
suse enterprise sap 15 SP7
9.0.36-13.1
fixed
suse enterprise server 12 SP4
9.0.36-3.71.1
fixed
suse enterprise server 12 SP5
9.0.115-3.160.1
fixed
suse enterprise server 15
9.0.36-3.84.1
fixed
suse enterprise server 15 SP1
9.0.36-4.63.1
fixed
suse enterprise server 15 SP2
9.0.36-13.1
fixed
suse enterprise server 15 SP3
9.0.36-13.1
fixed
suse enterprise server 15 SP4
9.0.36-13.1
fixed
suse enterprise server 15 SP5
9.0.36-13.1
fixed
suse enterprise server 15 SP6
9.0.36-13.1
fixed
suse enterprise server 15 SP7
9.0.36-13.1
fixed
tomcat-servlet-4_0-api
suse enterprise sap 12 SP5
9.0.36-3.71.1
fixed
suse enterprise sap 15
9.0.36-3.84.1
fixed
suse enterprise sap 15 SP1
9.0.36-4.63.1
fixed
suse enterprise sap 15 SP2
9.0.36-13.1
fixed
suse enterprise sap 15 SP3
9.0.36-13.1
fixed
suse enterprise sap 15 SP4
9.0.36-13.1
fixed
suse enterprise sap 15 SP5
9.0.36-13.1
fixed
suse enterprise sap 15 SP6
9.0.36-13.1
fixed
suse enterprise sap 15 SP7
9.0.36-13.1
fixed
suse enterprise server 12 SP4
9.0.36-3.71.1
fixed
suse enterprise server 12 SP5
9.0.115-3.160.1
fixed
suse enterprise server 15
9.0.36-3.84.1
fixed
suse enterprise server 15 SP1
9.0.36-4.63.1
fixed
suse enterprise server 15 SP2
9.0.36-13.1
fixed
suse enterprise server 15 SP3
9.0.36-13.1
fixed
suse enterprise server 15 SP4
9.0.36-13.1
fixed
suse enterprise server 15 SP5
9.0.36-13.1
fixed
suse enterprise server 15 SP6
9.0.36-13.1
fixed
suse enterprise server 15 SP7
9.0.36-13.1
fixed
tomcat-webapps
suse enterprise sap 12 SP5
9.0.36-3.71.1
fixed
suse enterprise sap 15
9.0.36-3.84.1
fixed
suse enterprise sap 15 SP1
9.0.36-4.63.1
fixed
suse enterprise sap 15 SP2
9.0.36-13.1
fixed
suse enterprise sap 15 SP3
9.0.36-13.1
fixed
suse enterprise sap 15 SP4
9.0.36-13.1
fixed
suse enterprise sap 15 SP5
9.0.36-13.1
fixed
suse enterprise sap 15 SP6
9.0.36-13.1
fixed
suse enterprise sap 15 SP7
9.0.36-13.1
fixed
suse enterprise server 12 SP4
9.0.36-3.71.1
fixed
suse enterprise server 12 SP5
9.0.115-3.160.1
fixed
suse enterprise server 15
9.0.36-3.84.1
fixed
suse enterprise server 15 SP1
9.0.36-4.63.1
fixed
suse enterprise server 15 SP2
9.0.36-13.1
fixed
suse enterprise server 15 SP3
9.0.36-13.1
fixed
suse enterprise server 15 SP4
9.0.36-13.1
fixed
suse enterprise server 15 SP5
9.0.36-13.1
fixed
suse enterprise server 15 SP6
9.0.36-13.1
fixed
suse enterprise server 15 SP7
9.0.36-13.1
fixed