Resource exhaustion in Apache Tomcat - CVE-2021-42340
Published: October 15, 2021
Vulnerability identifier: #VU57389
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-42340
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak when processing HTTP connections. A remote attacker can initiate multiple HTTP connections with the web server and consume all available memory on the system.
Affected software
Apache Tomcat
JBoss Web Server
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
openEuler
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM UrbanCode Release
IBM Rational Build Forge
Oracle Communications Diameter Signaling Router
Oracle SD-WAN Edge
Dell Secure Connect Gateway
IBM Sterling Control Center
Oracle Communications Session Report Manager
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Agile Engineering Data Management
Storage Protect Plus Server
MySQL Enterprise Monitor
Big Data Spatial and Graph
tomcat9 (Debian package)
Tomcat
tomcat
tomcat-jsvc
tomcat-help
pki-servlet-engine (Red Hat package)
Oracle Agile PLM Framework
Oracle Communications Instant Messaging Server
Oracle Commerce Guided Search
Oracle Managed File Transfer
Oracle Communications Element Manager
Oracle Communications Session Route Manager
Oracle Hospitality Cruise Shipboard Property Management System
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
SAN Volume Controller and Storwize Family
JBoss Web Server
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
openEuler
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM UrbanCode Release
IBM Rational Build Forge
Oracle Communications Diameter Signaling Router
Oracle SD-WAN Edge
Dell Secure Connect Gateway
IBM Sterling Control Center
Oracle Communications Session Report Manager
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Agile Engineering Data Management
Storage Protect Plus Server
MySQL Enterprise Monitor
Big Data Spatial and Graph
tomcat9 (Debian package)
Tomcat
tomcat
tomcat-jsvc
tomcat-help
pki-servlet-engine (Red Hat package)
Oracle Agile PLM Framework
Oracle Communications Instant Messaging Server
Oracle Commerce Guided Search
Oracle Managed File Transfer
Oracle Communications Element Manager
Oracle Communications Session Route Manager
Oracle Hospitality Cruise Shipboard Property Management System
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
SAN Volume Controller and Storwize Family
How to mitigate CVE-2021-42340
Install updates from vendor's website.
Apache Tomcat - addressed in versions 8.5.72, 9.0.54, 10.0.12, 10.1.0-M6
JBoss Web Server - update to 5.6.0
IBM UrbanCode Release - update to 6.2.5.6
IBM Rational Build Forge - update to 8.0.0.22
tomcat9 (Debian package) - update to 9.0.43-2~deb11u3
Big Data Spatial and Graph - update to 23.1
Tomcat - update to D.9.0.87.01
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell Secure Connect Gateway - update to 5.20.00.10
IBM Sterling Control Center - update to 6.2.1.0.14
SAN Volume Controller and Storwize Family - addressed in versions 8.4.0.6, 8.4.2.1
Oracle Communications Element Manager - update to 9.0
Oracle Communications Session Report Manager - update to 9.0
Oracle Communications Session Route Manager - update to 9.0
tomcat - update to 9.0.10-22
tomcat-jsvc - update to 9.0.10-22
tomcat-help - update to 9.0.10-22
pki-servlet-engine (Red Hat package) - update to 9.0.50-1.el9
Storage Protect Plus Server - update to 10.1.16.1
JBoss Web Server - update to 5.6.0
IBM UrbanCode Release - update to 6.2.5.6
IBM Rational Build Forge - update to 8.0.0.22
tomcat9 (Debian package) - update to 9.0.43-2~deb11u3
Big Data Spatial and Graph - update to 23.1
Tomcat - update to D.9.0.87.01
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell Secure Connect Gateway - update to 5.20.00.10
IBM Sterling Control Center - update to 6.2.1.0.14
SAN Volume Controller and Storwize Family - addressed in versions 8.4.0.6, 8.4.2.1
Oracle Communications Element Manager - update to 9.0
Oracle Communications Session Report Manager - update to 9.0
Oracle Communications Session Route Manager - update to 9.0
tomcat - update to 9.0.10-22
tomcat-jsvc - update to 9.0.10-22
tomcat-help - update to 9.0.10-22
pki-servlet-engine (Red Hat package) - update to 9.0.50-1.el9
Storage Protect Plus Server - update to 10.1.16.1
External References
Related Security Bulletins
- Denial of service in Apache Tomcat
- Amazon Linux AMI update for tomcat8
- Debian update for tomcat9
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Resource exhaustion in Oracle SD-WAN Edge
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Resource exhaustion in Oracle Hospitality Cruise Shipboard Property Management System
- Multiple vulnerabilities in Oracle Commerce Guided Search
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Resource exhaustion in Oracle Communications Instant Messaging Server
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Multiple vulnerabilities in Management Cloud Engine
- Multiple vulnerabilities in Oracle Communications Session Route Manager
- Multiple vulnerabilities in Oracle Communications Session Report Manager
- Multiple vulnerabilities in Oracle Communications Element Manager
- Multiple vulnerabilities in Oracle Agile PLM Framework
- Resource exhaustion in IBM Rational Build Forge
- Multiple vulnerabilities in Big Data Spatial and Graph
- Resource exhaustion in Oracle Managed File Transfer
- Multiple vulnerabilities in Oracle Agile Engineering Data Management
- Denial of service in IBM UrbanCode Release
- Gentoo update for Apache Tomcat
- Resource exhaustion in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Resource exhaustion in IBM SAN Volume Controller and Storwize Family
- Red Hat Enterprise Linux 9 update for pki-servlet-engine
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- Multiple vulnerabilities in Dell Secure Connect Gateway
- openEuler update for tomcat
- Multiple vulnerabilities in IBM Storage Protect Plus Server
- HP-UX update for Tomcat
- Multiple vulnerabilities in IBM Control Center