CVE-2021-42340 Details
Description
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-772 | Missing Release of Resource after Effective Lifetime | [email protected] |
| CWE-772 | Missing Release of Resource after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | >= 8.5.60, < 8.5.72 >= 9.0.40, < 9.0.54 >= 10.0.1, < 10.0.12 10.0.0 milestone10 10.1.0 milestone1 10.1.0 milestone2 10.1.0 milestone3 10.1.0 milestone4 10.1.0 milestone5 |
CPE
Remediation
| |
| netapp hci | All versions |
CPE
Remediation
| |
| netapp management services for element software | All versions |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
| oracle agile engineering data management | 6.2.1.0 |
CPE
Remediation
| |
| oracle big data spatial and graph | < 23.1 |
CPE
Remediation
| |
| oracle communications diameter signaling router | >= 8.0.0.0, <= 8.5.0.2 |
CPE
Remediation
| |
| oracle hospitality cruise shipboard property management system | 20.1.0 |
CPE
Remediation
| |
| oracle managed file transfer | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle middleware common libraries and tools | 12.2.1.4.0 |
CPE
Remediation
| |
| oracle payment interface | 19.1 20.3 |
CPE
Remediation
| |
| oracle retail customer insights | 15.0.2 16.0.2 |
CPE
Remediation
| |
| oracle retail data extractor for merchandising | 15.0.2 16.0.2 |
CPE
Remediation
| |
| oracle retail eftlink | 21.0.0 |
CPE
Remediation
| |
| oracle retail financial integration | 16.0.1 19.0.0 |
CPE
Remediation
| |
| oracle retail store inventory management | 14.0.4.13 14.1.3.5 14.1.3.14 15.0.3.3 15.0.3.8 16.0.3.7 |
CPE
Remediation
| |
| oracle sd-wan edge | 9.0 9.1 |
CPE
Remediation
| |
| oracle taleo platform | All versions |
CPE
Remediation
| |
Change History
19 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Oct 27, 2022 | Modified Analysis | [email protected] |
| Aug 21, 2022 | CVE Modified | [email protected] |
| Jul 25, 2022 | CVE Modified | [email protected] |
| May 2, 2022 | Modified Analysis | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Mar 29, 2022 | Modified Analysis | [email protected] |
| Mar 23, 2022 | CVE Modified | [email protected] |
| Feb 7, 2022 | CVE Modified | [email protected] |
| Dec 4, 2021 | Modified Analysis | [email protected] |
| Nov 12, 2021 | CVE Modified | [email protected] |
| Nov 10, 2021 | CVE Modified | [email protected] |
| Nov 5, 2021 | Modified Analysis | [email protected] |
| Nov 4, 2021 | CVE Modified | [email protected] |
| Oct 21, 2021 | CVE Modified | [email protected] |
| Oct 20, 2021 | Initial Analysis | [email protected] |