Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Network
0

CVE-2021-42340

Disclosure Date: October 14, 2021
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
7.5 High
Impact Score:
3.6
Exploitability Score:
3.9
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
None
Availability (A):
High

General Information

Vendors

  • apache,
  • debian,
  • netapp,
  • oracle

Products

  • agile engineering data management 6.2.1.0,
  • big data spatial and graph,
  • communications diameter signaling router,
  • debian linux 11.0,
  • hci -,
  • hospitality cruise shipboard property management system 20.1.0,
  • managed file transfer 12.2.1.3.0,
  • managed file transfer 12.2.1.4.0,
  • management services for element software -,
  • middleware common libraries and tools 12.2.1.4.0,
  • payment interface 19.1,
  • payment interface 20.3,
  • retail customer insights 15.0.2,
  • retail customer insights 16.0.2,
  • retail data extractor for merchandising 15.0.2,
  • retail data extractor for merchandising 16.0.2,
  • retail eftlink 21.0.0,
  • retail financial integration 16.0.1,
  • retail financial integration 19.0.0,
  • retail store inventory management 14.0.4.13,
  • retail store inventory management 14.1.3.14,
  • retail store inventory management 14.1.3.5,
  • retail store inventory management 15.0.3.3,
  • retail store inventory management 15.0.3.8,
  • retail store inventory management 16.0.3.7,
  • sd-wan edge 9.0,
  • sd-wan edge 9.1,
  • taleo platform,
  • tomcat,
  • tomcat 10.0.0,
  • tomcat 10.1.0
Technical Analysis