CVE-2021-42340

HIGHCVSS 7.5/10EPSS 11.00%

Last modified

CVE-2021-42340 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. EPSS estimates a 11.00% chance of exploitation in the next 30 days.

Description

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
11.00%

95.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
ApacheTomcat>= 8.5.60, < 8.5.72
ApacheTomcat>= 9.0.40, < 9.0.54
ApacheTomcat>= 10.0.1, < 10.0.12
ApacheTomcat10.0.0Milestone10
ApacheTomcat10.1.0Milestone1
NetappHciAll versions
NetappManagement Services For Element SoftwareAll versions
DebianDebian Linux11.0
OracleAgile Engineering Data Management6.2.1.0
OracleBig Data Spatial And Graph< 23.1
OracleCommunications Diameter Signaling Router>= 8.0.0.0, <= 8.5.0.2
OracleHospitality Cruise Shipboard Property Management System20.1.0
OracleManaged File Transfer12.2.1.3.0
OracleManaged File Transfer12.2.1.4.0
OracleMiddleware Common Libraries And Tools12.2.1.4.0
OraclePayment Interface19.1
OraclePayment Interface20.3
OracleRetail Customer Insights15.0.2
OracleRetail Customer Insights16.0.2
OracleRetail Data Extractor For Merchandising15.0.2
OracleRetail Data Extractor For Merchandising16.0.2
OracleRetail Eftlink21.0.0
OracleRetail Financial Integration16.0.1
OracleRetail Financial Integration19.0.0
OracleRetail Store Inventory Management14.0.4.13
OracleRetail Store Inventory Management14.1.3.5
OracleRetail Store Inventory Management14.1.3.14
OracleRetail Store Inventory Management15.0.3.3
OracleRetail Store Inventory Management15.0.3.8
OracleRetail Store Inventory Management16.0.3.7
OracleSd-Wan Edge9.0
OracleSd-Wan Edge9.1
OracleTaleo PlatformAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-42340?
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
How severe is CVE-2021-42340?
CVE-2021-42340 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 11.00% probability of exploitation in the next 30 days.
How do I fix CVE-2021-42340?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-42340?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST