 
                            ...
The Apache Geronimo and Tomcat vulnerability GERONIMO-4574, reported in March 2009, resulted from PolicyContext handler data objects being set in a thread and never released, causing these data objects to remain in memory longer than necessary.
Bibliography
| [API 2013] | |
| Item 6, "Eliminate Obsolete Object References" | |
| "Garbage Collection Concepts and Programming Tips" | |
| Java Theory and Practice: Garbage Collection and Performance | |
| [Lo 2005] | |
| [Oracle 2010a] | Java SE 6 HotSpot™ Virtual Machine Garbage Collection Tuning | 
...