QID 730242

Date Published: 2021-11-04

QID 730242: Apache Tomcat Denial of Service (DoS) Vulnerability

Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.

A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset between requests.

Affected Versions:
Apache Tomcat 10.1.0-M1 to 10.1.0-M5
Apache Tomcat 10.0.0-M10 to 10.0.11
Apache Tomcat 9.0.40 to 9.0.53
Apache Tomcat 8.5.60 to 8.5.71

QID Detection Logic (Unauthenticated):
The QID checks for vulnerable version by sending a GET /QUALYS730242 HTTP/1.0 request which helps in retrieving the installed version of Apache Tomcat in the banner of the response.

Successful exploitation of the vulnerability can allow an attacker to trigger a DoS via an OutOfMemoryError.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Upgrade to the Apache Tomcat 10.1.0-M6, 10.0.12, 9.0.54, 8.5.72 versions or to the latest version of Apache Tomcat. Please refer to Apache Tomcat Security Advisory.

    CVEs related to QID 730242

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-42340 URL Logo mail-archives.us.apache.org/mod_mbox/www-announce/202110.mbox/%3C9b8b83e3-7fec-a26d-7780-e5d4a85f7df6%40apache.org%3E