漏洞信息详情
Apache Tomcat 安全漏洞
漏洞简介
Apache Tomcat是美国阿帕奇(Apache)基金会的一款轻量级Web应用服务器。该程序实现了对Servlet和JavaServer Page(JSP)的支持。
Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0存在安全漏洞,该漏洞源于Tomcat实例仍然容易受到CVE-2020-9494的攻击。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E
参考网址
来源:MLIST
链接:https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cusers.tomcat.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r732b2ca289dc02df2de820e8775559abd6c207f159e39f559547a085@%3Cusers.tomcat.apache.org%3E
来源:CONFIRM
链接:https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9@%3Cdev.tomcat.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f@%3Cusers.tomcat.apache.org%3E
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210409-0002/
来源:MLIST
链接:https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cannounce.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cdev.tomcat.apache.org%3E
来源:N/A
链接:https://www.oracle.com//security-alerts/cpujul2021.html
来源:MLIST
链接:https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77@%3Cusers.tomcat.apache.org%3E
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2021/03/01/2
来源:MLIST
链接:https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc@%3Cusers.tomcat.apache.org%3E
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuoct2021.html
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-4891
来源:MLIST
链接:https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cannounce.tomcat.apache.org%3E
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0938
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-data-risk-manager-is-affected-by-multiple-vulnerabilities-4/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164101/Red-Hat-Security-Advisory-2021-3425-01.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-siem-is-vulnerable-to-using-components-with-known-vulnerabilities-9/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2558
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0742
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-open-source-apache-tomcat-vulnerabilities-affect-ibm-tivoli-application-dependency-discovery-manager-cve-2021-25122-cve-2021-25329/
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021063003
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021041624
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1130
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163307/Red-Hat-Security-Advisory-2021-2562-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1103
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021092209
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1222
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1375
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1485
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Apache-Tomcat-code-execution-via-PersistenceManager-34714
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0915.2
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2261
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3051
受影响实体
暂无
补丁
- Apache Tomcat 安全漏洞的修复措施<!--2021-3-1-->
还没有评论,来说两句吧...