7.5
CVSSv3

CVE-2021-42340

Published: 14/10/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A security issue has been found in Apache Tomcat prior to 10.0.12, 9.0.54 and 8.5.72. The fix for bug 63362 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the WebSocket connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomcat 10.0.0

apache tomcat 10.1.0

apache tomcat

netapp hci -

netapp management services for element software -

debian debian linux 11.0

oracle managed file transfer 12.2.1.3.0

oracle sd-wan edge 9.0

oracle agile engineering data management 6.2.1.0

oracle managed file transfer 12.2.1.4.0

oracle hospitality cruise shipboard property management system 20.1.0

oracle sd-wan edge 9.1

oracle communications diameter signaling router

oracle big data spatial and graph

oracle middleware common libraries and tools 12.2.1.4.0

oracle retail customer insights 15.0.2

oracle retail customer insights 16.0.2

oracle taleo platform

oracle payment interface 20.3

oracle payment interface 19.1

oracle retail eftlink 21.0.0

oracle retail data extractor for merchandising 16.0.2

oracle retail data extractor for merchandising 15.0.2

oracle retail financial integration 19.0.0

oracle retail financial integration 16.0.1

oracle retail store inventory management 14.1.3.5

oracle retail store inventory management 14.1.3.14

oracle retail store inventory management 15.0.3.3

oracle retail store inventory management 15.0.3.8

oracle retail store inventory management 16.0.3.7

oracle retail store inventory management 14.0.4.13

Vendor Advisories

Apache Tomcat, the servlet and JSP engine, did not properly release an HTTP upgrade connection for WebSocket connections once the WebSocket connection was closed This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError For the stable distribution (bullseye), this problem has been fixed in version 904 ...
Synopsis Important: Red Hat support for Spring Boot 2510 update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift Application RuntimesRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Important: Red Hat Fuse 7110 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 710 to 711) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security has rated this update ...
A memory leak flaw was found in Apache Tomcat, where an HTTP upgrade connection does not release for WebSocket connections once the WebSocket connection is closed If a sufficient number of such requests are made, an OutOfMemoryError occurs, leading to a denial of service The highest threat from this vulnerability is to system availability (CVE-2 ...
A memory leak flaw was found in Apache Tomcat, where an HTTP upgrade connection does not release for WebSocket connections once the WebSocket connection is closed If a sufficient number of such requests are made, an OutOfMemoryError occurs, leading to a denial of service The highest threat from this vulnerability is to system availability (CVE-2 ...
A memory leak flaw was found in Apache Tomcat, where an HTTP upgrade connection does not release for WebSocket connections once the WebSocket connection is closed If a sufficient number of such requests are made, an OutOfMemoryError occurs, leading to a denial of service The highest threat from this vulnerability is to system availability (CVE-2 ...
No description is available for this CVE ...
A security issue has been found in Apache Tomcat before versions 10012, 9054 and 8572 The fix for bug 63362 introduced a memory leak The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the WebSocket connection was closed This created a memory leak that, over time, could lea ...