QID 150451

Date Published: 2022-01-20

QID 150451: Apache Tomcat Denial of Service Vulnerability (CVE-2021-42340)

Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.

Apache Tomcat is vulnerable to a denial of service, caused by a memory leak flaw in WebSocket connections. By sending a specially-crafted request using OutOfMemoryError, a remote attacker could exploit this vulnerability to cause a denial of service condition.

Versions Affected:
Apache Tomcat 10.1.0-M1 to 10.1.0-M5
Apache Tomcat 10.0.0-M10 to 10.0.11
Apache Tomcat 9.0.40 to 9.0.53
Apache Tomcat 8.5.60 to 8.5.71

Successful exploitation of the vulnerability can allow an attacker to trigger a DoS via an OutOfMemoryError.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Upgrade to the Apache Tomcat 10.1.0-M6, 10.0.12, 9.0.54, 8.5.72 versions or to the latest version of Apache Tomcat. Please refer to Apache Tomcat Security Advisory.

    CVEs related to QID 150451

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-42340 URL Logo lists.apache.org/thread/q33k672q3q3zf114fpf7vfoycghtsbxd
    CVE-2021-42340 URL Logo lists.apache.org/thread/5k2dr6n8sw9g6swk7jyrkvk6wxqf6kx6