VYPR
High severity7.5NVD Advisory· Published Jul 12, 2021· Updated Jun 17, 2026

CVE-2021-30639

CVE-2021-30639

Description

A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset between requests. This meant that once a non-blocking I/O error occurred, all future requests handled by that request object would fail. Users were able to trigger non-blocking I/O errors, e.g. by dropping a connection, thereby creating the possibility of triggering a DoS. Applications that do not use non-blocking I/O are not exposed to this vulnerability. This issue affects Apache Tomcat 10.0.3 to 10.0.4; 9.0.44; 8.5.64.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.tomcat:tomcatMaven
>= 10.0.3, < 10.0.510.0.5
org.apache.tomcat:tomcatMaven
>= 9.0.0, < 9.0.459.0.45
org.apache.tomcat:tomcatMaven
< 8.5.658.5.65

Affected products

20
  • osv-coords2 versions
    >= 8.5.64, < 8.5.65+ 1 more
    • (no CPE)range: >= 8.5.64, < 8.5.65
    • (no CPE)range: >= 10.0.3, < 10.0.5
  • Apache Software Foundation/Apache Tomcatv5
    Range: Apache Tomcat 10 10.0.3 to 10.0.4
  • Apache/Tomcat4 versions
    cpe:2.3:a:apache:tomcat:8.5.64:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:apache:tomcat:8.5.64:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:9.0.44:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:10.0.4:*:*:*:*:*:*:*
  • cpe:2.3:a:mcafee:epolicy_orchestrator:*:*:*:*:*:*:*:*+ 11 more
    • cpe:2.3:a:mcafee:epolicy_orchestrator:*:*:*:*:*:*:*:*range: <5.10.0
    • cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:-:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_1:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_10:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_2:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_3:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_4:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_5:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_6:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_7:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_8:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_9:*:*:*:*:*:*
  • cpe:2.3:a:oracle:big_data_spatial_and_graph:*:*:*:*:*:*:*:*
    Range: <23.1

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.