HIGH · 7.5

CVE-2021-42340

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics fo...

Vulnerability Description

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ApacheTomcat>= 8.5.60, < 8.5.72
NetappHci-
NetappManagement Services For Element Software-
DebianDebian Linux11.0
OracleAgile Engineering Data Management6.2.1.0
OracleBig Data Spatial And Graph< 23.1
OracleCommunications Diameter Signaling Router>= 8.0.0.0, <= 8.5.0.2
OracleHospitality Cruise Shipboard Property Management System20.1.0
OracleManaged File Transfer12.2.1.3.0
OracleMiddleware Common Libraries And Tools12.2.1.4.0
OraclePayment Interface19.1
OracleRetail Customer Insights15.0.2
OracleRetail Data Extractor For Merchandising15.0.2
OracleRetail Eftlink21.0.0
OracleRetail Financial Integration16.0.1
OracleRetail Store Inventory Management14.0.4.13
OracleSd-Wan Edge9.0
OracleTaleo PlatformAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-42340?

CVE-2021-42340 is a vulnerability with a CVSS score of 7.5 (HIGH). The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics fo...

How severe is CVE-2021-42340?

CVE-2021-42340 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-42340?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Netapp Hci, Netapp Management Services For Element Software, Debian Debian Linux, Oracle Agile Engineering Data Management.