QID 730505
Date Published: 2022-05-31
QID 730505: Apache Tomcat Denial of Service (DoS) Vulnerability (CVE-2021-41079)
Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.
A vulnerability in Apache Tomcat created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
Affected Versions:
Apache Tomcat 10.1.0-M1 to 10.1.0-M5
Apache Tomcat 10.0.0-M10 to 10.0.11
Apache Tomcat 9.0.40 to 9.0.53
Apache Tomcat 8.5.60 to 8.5.71
QID Detection Logic (Unauthenticated):
The QID checks for vulnerable version by sending a GET /QUALYS730242 HTTP/1.0 request which helps in retrieving the installed version of Apache Tomcat in the banner of the response.
Successful exploitation of the vulnerability can allow an attacker to trigger a DoS via an OutOfMemoryError.
Solution
Upgrade to the latest version of Apache Tomcat. Please refer to Apache Tomcat Security Advisory.
Vendor References
- CVE-2021-41079 -
lists.apache.org/thread/5dnn1owvq9fzyyc0zbgn50tk3hkjp2ds
CVEs related to QID 730505
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-41079 |
|