// For flags

CVE-2021-42340

DoS via memory leak with WebSocket connections

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

La corrección del bug 63362 presente en Apache Tomcat versiones 10.1.0-M1 hasta 10.1.0-M5, versiones 10.0.0-M1 hasta 10.0.11, versiones 9.0.40 hasta 9.0.53 y versiones 8.5.60 hasta 8.5.71, introducía una pérdida de memoria. El objeto introducido para recopilar métricas para las conexiones de actualización HTTP no se liberaba para las conexiones WebSocket una vez que se cerraba la conexión. Esto creaba una pérdida de memoria que, con el tiempo, podía conllevar a una denegación de servicio por medio de un OutOfMemoryError

A memory leak flaw was found in Apache Tomcat, where an HTTP upgrade connection does not release for WebSocket connections once the WebSocket connection is closed. If a sufficient number of such requests are made, an OutOfMemoryError occurs, leading to a denial of service. The highest threat from this vulnerability is to system availability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-10-13 CVE Reserved
  • 2021-10-14 CVE Published
  • 2024-06-29 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-772: Missing Release of Resource after Effective Lifetime
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
>= 8.5.60 < 8.5.72
Search vendor "Apache" for product "Tomcat" and version " >= 8.5.60 < 8.5.72"
-
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
>= 9.0.40 < 9.0.54
Search vendor "Apache" for product "Tomcat" and version " >= 9.0.40 < 9.0.54"
-
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
>= 10.0.1 < 10.0.12
Search vendor "Apache" for product "Tomcat" and version " >= 10.0.1 < 10.0.12"
-
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
10.0.0
Search vendor "Apache" for product "Tomcat" and version "10.0.0"
milestone10
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
10.1.0
Search vendor "Apache" for product "Tomcat" and version "10.1.0"
milestone1
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
10.1.0
Search vendor "Apache" for product "Tomcat" and version "10.1.0"
milestone2
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
10.1.0
Search vendor "Apache" for product "Tomcat" and version "10.1.0"
milestone3
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
10.1.0
Search vendor "Apache" for product "Tomcat" and version "10.1.0"
milestone4
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
10.1.0
Search vendor "Apache" for product "Tomcat" and version "10.1.0"
milestone5
Affected
Netapp
Search vendor "Netapp"
Hci
Search vendor "Netapp" for product "Hci"
--
Affected
Netapp
Search vendor "Netapp"
Management Services For Element Software
Search vendor "Netapp" for product "Management Services For Element Software"
--
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
11.0
Search vendor "Debian" for product "Debian Linux" and version "11.0"
-
Affected
Oracle
Search vendor "Oracle"
Agile Engineering Data Management
Search vendor "Oracle" for product "Agile Engineering Data Management"
6.2.1.0
Search vendor "Oracle" for product "Agile Engineering Data Management" and version "6.2.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Big Data Spatial And Graph
Search vendor "Oracle" for product "Big Data Spatial And Graph"
< 23.1
Search vendor "Oracle" for product "Big Data Spatial And Graph" and version " < 23.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
>= 8.0.0.0 <= 8.5.0.2
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " >= 8.0.0.0 <= 8.5.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Hospitality Cruise Shipboard Property Management System
Search vendor "Oracle" for product "Hospitality Cruise Shipboard Property Management System"
20.1.0
Search vendor "Oracle" for product "Hospitality Cruise Shipboard Property Management System" and version "20.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Managed File Transfer
Search vendor "Oracle" for product "Managed File Transfer"
12.2.1.3.0
Search vendor "Oracle" for product "Managed File Transfer" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Managed File Transfer
Search vendor "Oracle" for product "Managed File Transfer"
12.2.1.4.0
Search vendor "Oracle" for product "Managed File Transfer" and version "12.2.1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Middleware Common Libraries And Tools
Search vendor "Oracle" for product "Middleware Common Libraries And Tools"
12.2.1.4.0
Search vendor "Oracle" for product "Middleware Common Libraries And Tools" and version "12.2.1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Payment Interface
Search vendor "Oracle" for product "Payment Interface"
19.1
Search vendor "Oracle" for product "Payment Interface" and version "19.1"
-
Affected
Oracle
Search vendor "Oracle"
Payment Interface
Search vendor "Oracle" for product "Payment Interface"
20.3
Search vendor "Oracle" for product "Payment Interface" and version "20.3"
-
Affected
Oracle
Search vendor "Oracle"
Retail Customer Insights
Search vendor "Oracle" for product "Retail Customer Insights"
15.0.2
Search vendor "Oracle" for product "Retail Customer Insights" and version "15.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Customer Insights
Search vendor "Oracle" for product "Retail Customer Insights"
16.0.2
Search vendor "Oracle" for product "Retail Customer Insights" and version "16.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Data Extractor For Merchandising
Search vendor "Oracle" for product "Retail Data Extractor For Merchandising"
15.0.2
Search vendor "Oracle" for product "Retail Data Extractor For Merchandising" and version "15.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Data Extractor For Merchandising
Search vendor "Oracle" for product "Retail Data Extractor For Merchandising"
16.0.2
Search vendor "Oracle" for product "Retail Data Extractor For Merchandising" and version "16.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Eftlink
Search vendor "Oracle" for product "Retail Eftlink"
21.0.0
Search vendor "Oracle" for product "Retail Eftlink" and version "21.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Financial Integration
Search vendor "Oracle" for product "Retail Financial Integration"
16.0.1
Search vendor "Oracle" for product "Retail Financial Integration" and version "16.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Financial Integration
Search vendor "Oracle" for product "Retail Financial Integration"
19.0.0
Search vendor "Oracle" for product "Retail Financial Integration" and version "19.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Store Inventory Management
Search vendor "Oracle" for product "Retail Store Inventory Management"
14.0.4.13
Search vendor "Oracle" for product "Retail Store Inventory Management" and version "14.0.4.13"
-
Affected
Oracle
Search vendor "Oracle"
Retail Store Inventory Management
Search vendor "Oracle" for product "Retail Store Inventory Management"
14.1.3.5
Search vendor "Oracle" for product "Retail Store Inventory Management" and version "14.1.3.5"
-
Affected
Oracle
Search vendor "Oracle"
Retail Store Inventory Management
Search vendor "Oracle" for product "Retail Store Inventory Management"
14.1.3.14
Search vendor "Oracle" for product "Retail Store Inventory Management" and version "14.1.3.14"
-
Affected
Oracle
Search vendor "Oracle"
Retail Store Inventory Management
Search vendor "Oracle" for product "Retail Store Inventory Management"
15.0.3.3
Search vendor "Oracle" for product "Retail Store Inventory Management" and version "15.0.3.3"
-
Affected
Oracle
Search vendor "Oracle"
Retail Store Inventory Management
Search vendor "Oracle" for product "Retail Store Inventory Management"
15.0.3.8
Search vendor "Oracle" for product "Retail Store Inventory Management" and version "15.0.3.8"
-
Affected
Oracle
Search vendor "Oracle"
Retail Store Inventory Management
Search vendor "Oracle" for product "Retail Store Inventory Management"
16.0.3.7
Search vendor "Oracle" for product "Retail Store Inventory Management" and version "16.0.3.7"
-
Affected
Oracle
Search vendor "Oracle"
Sd-wan Edge
Search vendor "Oracle" for product "Sd-wan Edge"
9.0
Search vendor "Oracle" for product "Sd-wan Edge" and version "9.0"
-
Affected
Oracle
Search vendor "Oracle"
Sd-wan Edge
Search vendor "Oracle" for product "Sd-wan Edge"
9.1
Search vendor "Oracle" for product "Sd-wan Edge" and version "9.1"
-
Affected
Oracle
Search vendor "Oracle"
Taleo Platform
Search vendor "Oracle" for product "Taleo Platform"
*-
Affected