cbcvebase.
CVE-2021-42340
published 2021-10-14

CVE-2021-42340: The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat
apachetomcat
apachetomcat>= 10.0.1 < 10.0.1210.0.12
apachetomcat>= 8.5.60 < 8.5.728.5.72
apachetomcat>= 9.0.40 < 9.0.549.0.54
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
debiandebian_linux
debiantomcat9< tomcat9 9.0.54-1 (bookworm)tomcat9 9.0.54-1 (bookworm)
oracleagile_engineering_data_management
oraclebig_data_spatial_and_graph< 23.123.1
oraclecommunications_diameter_signaling_router8.0.0.0 – 8.5.0.2
oraclehospitality_cruise_shipboard_property_management_system
oraclemanaged_file_transfer
oraclemanaged_file_transfer
oraclemiddleware_common_libraries_and_tools
oraclepayment_interface
oraclepayment_interface
oracleretail_customer_insights
oracleretail_customer_insights
oracleretail_data_extractor_for_merchandising
oracleretail_data_extractor_for_merchandising

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH