#VU51014 Resource management error in Apache Tomcat - CVE-2021-25122
Published: March 1, 2021
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper management of internal resources within the application when processing new h2c connection requests. A remote attacker can send specially crafted requests to the server and obtain contents of HTTP responses, served to other users.