Resource exhaustion in Apache Tomcat - CVE-2021-42340

 

Resource exhaustion in Apache Tomcat - CVE-2021-42340

Published: October 15, 2021


Vulnerability identifier: #VU57389
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-42340
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak when processing HTTP connections. A remote attacker can initiate multiple HTTP connections with the web server and consume all available memory on the system.

Affected software

Apache Tomcat
JBoss Web Server
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
openEuler
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM UrbanCode Release
IBM Rational Build Forge
Oracle Communications Diameter Signaling Router
Oracle SD-WAN Edge
Dell Secure Connect Gateway
IBM Sterling Control Center
Oracle Communications Session Report Manager
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Agile Engineering Data Management
Storage Protect Plus Server
MySQL Enterprise Monitor
Big Data Spatial and Graph
tomcat9 (Debian package)
Tomcat
tomcat
tomcat-jsvc
tomcat-help
pki-servlet-engine (Red Hat package)
Oracle Agile PLM Framework
Oracle Communications Instant Messaging Server
Oracle Commerce Guided Search
Oracle Managed File Transfer
Oracle Communications Element Manager
Oracle Communications Session Route Manager
Oracle Hospitality Cruise Shipboard Property Management System
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
SAN Volume Controller and Storwize Family

How to mitigate CVE-2021-42340

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.72, 9.0.54, 10.0.12, 10.1.0-M6
JBoss Web Server - update to 5.6.0
IBM UrbanCode Release - update to 6.2.5.6
IBM Rational Build Forge - update to 8.0.0.22
tomcat9 (Debian package) - update to 9.0.43-2~deb11u3
Big Data Spatial and Graph - update to 23.1
Tomcat - update to D.9.0.87.01
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell Secure Connect Gateway - update to 5.20.00.10
IBM Sterling Control Center - update to 6.2.1.0.14
SAN Volume Controller and Storwize Family - addressed in versions 8.4.0.6, 8.4.2.1
Oracle Communications Element Manager - update to 9.0
Oracle Communications Session Report Manager - update to 9.0
Oracle Communications Session Route Manager - update to 9.0
tomcat - update to 9.0.10-22
tomcat-jsvc - update to 9.0.10-22
tomcat-help - update to 9.0.10-22
pki-servlet-engine (Red Hat package) - update to 9.0.50-1.el9
Storage Protect Plus Server - update to 10.1.16.1

External References

Related Security Bulletins