CVE-2024-38286

Aliases:GHSA-7jqf-v358-p8g7BIT-tomcat-2024-38286RHSA-2024:8494RHSA-2024:8497RHSA-2024:8528RHSA-2024:8543RHSA-2024:8567RHSA-2024:8572DEBIAN-CVE-2024-38286CGA-6354-jr66-j3cpCGA-6pp6-r432-7rr3CGA-grww-8964-j9jwCGA-pxx4-pq98-vhh5
Advisory lineage Upstream: 0 Downstream: 19
Modified
Published: 07 Nov 2024, 07:37
Last modified:03 Nov 2025, 20:38

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.6 HIGH
v3.1 (cve.org)
EPSS Score
1.69% LOW
2% probability +1.29%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

07 Nov 2024, 07:37
Published
Vulnerability first disclosed
03 Nov 2025, 20:38
Last Modified
Vulnerability information updated

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.

CVSS Metrics

  • v4.0HIGHScore: 7.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H
  • v3.1HIGHScore: 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 1.69% Percentile: 76%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • apache software foundationapache tomcat

    ≥ 11.0.0-M1, ≤ 11.0.0-M20 | ≥ 10.1.0-M1, ≤ 10.1.24 | ≥ 9.0.13, ≤ 9.0.89 | ≥ 8.5.35, ≤ 8.5.100 | ≥ 7.0.92, ≤ 7.0.109

  • apachetomcat

    ≥ 9.0.13, < 9.0.90 | ≥ 10.1.1, < 10.1.25 | 10.1.0:milestone1 | 10.1.0:milestone10 | 10.1.0:milestone11 | 10.1.0:milestone12 | 10.1.0:milestone13 | 10.1.0:milestone14 | 10.1.0:milestone15 | 10.1.0:milestone16 | 10.1.0:milestone17 | 10.1.0:milestone18 | 10.1.0:milestone19 | 10.1.0:milestone2 | 10.1.0:milestone20 | 10.1.0:milestone3 | 10.1.0:milestone4 | 10.1.0:milestone5 | 10.1.0:milestone6 | 10.1.0:milestone7 | 10.1.0:milestone8 | 10.1.0:milestone9 | 11.0.0:milestone1 | 11.0.0:milestone10 | 11.0.0:milestone11 | 11.0.0:milestone12 | 11.0.0:milestone13 | 11.0.0:milestone14 | 11.0.0:milestone15 | 11.0.0:milestone16 | 11.0.0:milestone17 | 11.0.0:milestone18 | 11.0.0:milestone19 | 11.0.0:milestone2 | 11.0.0:milestone20 | 11.0.0:milestone3 | 11.0.0:milestone4 | 11.0.0:milestone5 | 11.0.0:milestone6 | 11.0.0:milestone7 | 11.0.0:milestone8 | 11.0.0:milestone9

  • chainguardtomcat-8.5.87

    all | < 8.5.87-r6

  • debiantomcat10

    < 10.1.34-0+deb12u1 | < 10.1.25-1 | < 10.1.25-1

  • debiantomcat9

    < 9.0.43-2~deb11u11 | < 9.0.70-2 | < 9.0.70-2 | < 9.0.70-2

  • org.apache.tomcattomcat-coyote

    ≥ 11.0.0-M1, < 11.0.0-M21 | ≥ 10.1.0-M1, < 10.1.25 | ≥ 9.0.13, < 9.0.90 | ≥ 8.5.35, ≤ 8.5.100 | ≥ 7.0.92, ≤ 7.0.109

  • org.apache.tomcattomcat-util

    ≥ 11.0.0-M1, < 11.0.0-M21 | ≥ 10.1.0-M1, < 10.1.25 | ≥ 9.0.13, < 9.0.90 | ≥ 8.5.35, ≤ 8.5.100 | ≥ 7.0.92, ≤ 7.0.109

  • org.apache.tomcat.embedtomcat-embed-core

    ≥ 11.0.0-M1, < 11.0.0-M21 | ≥ 10.1.0-M1, < 10.1.25 | ≥ 9.0.13, < 9.0.90 | ≥ 8.5.35, ≤ 8.5.100 | ≥ 7.0.92, ≤ 7.0.109

  • netappontap_tools

    9 | 10

  • redhatapache-commons-collections

    < 0:3.2.2-10.module+el8.1.0+3366+6dfb954c

  • redhatapache-commons-lang

    < 0:2.6-21.module+el8.1.0+3366+6dfb954c

  • redhatapache-commons-net

    < 0:3.6-3.module+el8.3.0+6805+72837426

  • redhatbea-stax

    < 0:1.2.0-16.module+el8.1.0+3366+6dfb954c

  • redhatbea-stax-api

    < 0:1.2.0-16.module+el8.1.0+3366+6dfb954c

  • redhatglassfish-fastinfoset

    < 0:1.2.13-9.module+el8.1.0+3366+6dfb954c

  • redhatglassfish-jaxb

    < 0:2.2.11-11.module+el8.1.0+3366+6dfb954c

  • redhatglassfish-jaxb-api

    < 0:2.2.12-8.module+el8.1.0+3366+6dfb954c

  • redhatglassfish-jaxb-core

    < 0:2.2.11-11.module+el8.1.0+3366+6dfb954c

  • redhatglassfish-jaxb-runtime

    < 0:2.2.11-11.module+el8.1.0+3366+6dfb954c

  • redhatglassfish-jaxb-txw2

    < 0:2.2.11-11.module+el8.1.0+3366+6dfb954c

  • redhatidm-pki-acme

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatidm-pki-base

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatidm-pki-base-java

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatidm-pki-ca

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatidm-pki-kra

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatidm-pki-server

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatidm-pki-symkey

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatidm-pki-symkey-debuginfo

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatidm-pki-tools

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatidm-pki-tools-debuginfo

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatjackson-annotations

    < 0:2.10.0-1.module+el8.2.0+5059+3eb3af25

  • redhatjackson-core

    < 0:2.10.0-1.module+el8.2.0+5059+3eb3af25

  • redhatjackson-databind

    < 0:2.10.0-1.module+el8.2.0+5059+3eb3af25

  • redhatjackson-jaxrs-json-provider

    < 0:2.9.9-1.module+el8.1.0+3832+9784644d

  • redhatjackson-jaxrs-providers

    < 0:2.9.9-1.module+el8.1.0+3832+9784644d

  • redhatjackson-module-jaxb-annotations

    < 0:2.7.6-4.module+el8.1.0+3366+6dfb954c

  • redhatjakarta-commons-httpclient

    < 1:3.1-28.module+el8.1.0+3366+6dfb954c

  • redhatjavassist

    < 0:3.18.1-8.module+el8.1.0+3366+6dfb954c

  • redhatjavassist-javadoc

    < 0:3.18.1-8.module+el8.1.0+3366+6dfb954c

  • redhatjss

    < 0:4.9.4-1.module+el8.7.0+15532+95bac9ee

  • redhatjss-debuginfo

    < 0:4.9.4-1.module+el8.7.0+15532+95bac9ee

  • redhatjss-debugsource

    < 0:4.9.4-1.module+el8.7.0+15532+95bac9ee

  • redhatjss-javadoc

    < 0:4.9.4-1.module+el8.7.0+15532+95bac9ee

  • redhatldapjdk

    < 0:4.23.0-1.module+el8.5.0+11983+6ba118b4

  • redhatldapjdk-javadoc

    < 0:4.23.0-1.module+el8.5.0+11983+6ba118b4

  • redhatpki-core

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatpki-core-debuginfo

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatpki-core-debugsource

    < 0:10.14.3-3.module+el8.8.0+22366+77f9de5e

  • redhatpki-servlet-4.0-api

    < 1:9.0.50-1.el9_2.1 | < 1:9.0.30-1.module+el8.4.0+22383+8a8bb077.1 | < 1:9.0.43-4.el9_0.1 | < 1:9.0.7-16.module+el8.2.0+22384+93cade87.1 | < 1:9.0.30-3.module+el8.6.0+22385+e922a50e.1

  • redhatpki-servlet-engine

    < 1:9.0.50-1.el9_2.1 | < 1:9.0.30-1.module+el8.4.0+22383+8a8bb077.1 | < 1:9.0.43-4.el9_0.1 | < 1:9.0.62-1.module+el8.8.0+22367+4894538d | < 1:9.0.7-16.module+el8.2.0+22384+93cade87.1 | < 1:9.0.30-3.module+el8.6.0+22385+e922a50e.1

Showing first 50 affected entries in server-rendered view.

References (28)