← All CVEs

CVE-2021-42340

high · 7.5

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

7.5
CVSS
11.8%
EPSS (exploit prob.)
96th
EPSS percentile
2021-10-14
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-772

Affected products

VendorProductAffected versions
apachetomcat>= 8.5.60, < 8.5.72
apachetomcat>= 9.0.40, < 9.0.54
apachetomcat>= 10.0.1, < 10.0.12
apachetomcat10.0.0
apachetomcat10.1.0
apachetomcat10.1.0
apachetomcat10.1.0
apachetomcat10.1.0
apachetomcat10.1.0
netapphciall versions
netappmanagement_services_for_element_softwareall versions
debiandebian_linux11.0
oracleagile_engineering_data_management6.2.1.0
oraclebig_data_spatial_and_graph< 23.1
oraclecommunications_diameter_signaling_router>= 8.0.0.0, <= 8.5.0.2
oraclehospitality_cruise_shipboard_property_management_system20.1.0
oraclemanaged_file_transfer12.2.1.3.0
oraclemanaged_file_transfer12.2.1.4.0
oraclemiddleware_common_libraries_and_tools12.2.1.4.0
oraclepayment_interface19.1
oraclepayment_interface20.3
oracleretail_customer_insights15.0.2
oracleretail_customer_insights16.0.2
oracleretail_data_extractor_for_merchandising15.0.2
oracleretail_data_extractor_for_merchandising16.0.2
oracleretail_eftlink21.0.0
oracleretail_financial_integration16.0.1
oracleretail_financial_integration19.0.0
oracleretail_store_inventory_management14.0.4.13
oracleretail_store_inventory_management14.1.3.5
oracleretail_store_inventory_management14.1.3.14
oracleretail_store_inventory_management15.0.3.3
oracleretail_store_inventory_management15.0.3.8
oracleretail_store_inventory_management16.0.3.7
oraclesd-wan_edge9.0
oraclesd-wan_edge9.1
oracletaleo_platformall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-42340