Rewterz
Rewterz Threat Advisory – Multiple Linux Kernel Security Vulnerabilities
September 16, 2021
Rewterz
Rewterz Threat Alert – RedLine Malware – Active IOCs
September 17, 2021

Rewterz Threat Advisory – CVE-2021-41079 – Apache Tomcat Vulnerability

Severity

High

Analysis Summary

CVE-2021-41079

Apache Tomcat is vulnerable to a denial of service, caused by improper input validation of TLS packets. By sending a specially-crafted TLS packet, a remote attacker could exploit this vulnerability to cause an infinite loop, and results in a denial of service condition.

Impact

  • Denial of Service

Affected Vendors

Apache Tomcat

Affected Products

  • Apache Tomcat 10.0.0-M1
  • Apache Tomcat 10.0.2
  • Apache Tomcat 9.0.0-M1
  • Apache Tomcat 9.0.43

Remediation

Upgrade to the latest version of Apache Tomcat, available from the Apache Website.

http://tomcat.apache.org/