7.5

CVE-2021-42340

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheTomcat Version >= 8.5.60 < 8.5.72
ApacheTomcat Version >= 9.0.40 < 9.0.54
ApacheTomcat Version >= 10.0.1 < 10.0.12
ApacheTomcat Version10.0.0 Updatemilestone10
ApacheTomcat Version10.1.0 Updatemilestone1
ApacheTomcat Version10.1.0 Updatemilestone2
ApacheTomcat Version10.1.0 Updatemilestone3
ApacheTomcat Version10.1.0 Updatemilestone4
ApacheTomcat Version10.1.0 Updatemilestone5
NetappHci Version-
DebianDebian Linux Version11.0
OracleCommunications Diameter Signaling Router Version >= 8.0.0.0 <= 8.5.0.2
OracleManaged File Transfer Version12.2.1.3.0
OracleManaged File Transfer Version12.2.1.4.0
OraclePayment Interface Version19.1
OraclePayment Interface Version20.3
OracleRetail Customer Insights Version15.0.2
OracleRetail Customer Insights Version16.0.2
OracleRetail Eftlink Version21.0.0
OracleSd-wan Edge Version9.0
OracleSd-wan Edge Version9.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3% 0.861
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-772 Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.