CVE-2021-42340
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
Affected (37)
Products: Apache: Tomcat · Netapp: Hci, Management Services For Element Software · Debian: Debian Linux · +1 more
Show all products
Apache: Tomcat · Netapp: Hci, Management Services For Element Software · Debian: Debian Linux · Oracle: Agile Engineering Data Management, Big Data Spatial And Graph, Communications Diameter Signaling Router, Hospitality Cruise Shipboard Property Management System, Managed File Transfer, Middleware Common Libraries And Tools, Payment Interface, Retail Customer Insights, Retail Data Extractor For Merchandising, Retail Eftlink, Retail Financial Integration, Retail Store Inventory Management, Sd Wan Edge, Taleo Platform
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2.1.0 | |
| Before 23.1 | |
| From 8.0.0.0 to 8.5.0.2 | |
| Version 20.1.0 | |
| Version 12.2.1.3.0 | |
| Version 12.2.1.4.0 | |
| Version 19.1 | |
| Version 15.0.2 | |
| Version 15.0.2 | |
| Version 21.0.0 | |
| Version 16.0.1 | |
| Version 14.0.4.13 | |
| Version 9.0 | |
| All versions |
References (18)
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.