CVE-2024-38286

Aliases:GHSA-7jqf-v358-p8g7BIT-tomcat-2024-38286
Advisory lineage Upstream: 0 Downstream: 19
Modified
Published: 07 Nov 2024, 07:37
Last modified:03 Nov 2025, 20:38

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
8.6 HIGH
v3.1 (cve.org)
EPSS Score
0.41% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

07 Nov 2024, 07:37
Published
Vulnerability first disclosed
03 Nov 2025, 20:38
Last Modified
Vulnerability information updated

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.

CVSS Metrics

  • v4.0HIGHScore: 7.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H
  • v3.1HIGHScore: 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.41% Percentile: 62%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • apache software foundationapache tomcat

    ≥ 11.0.0-M1, ≤ 11.0.0-M20 | ≥ 10.1.0-M1, ≤ 10.1.24 | ≥ 9.0.13, ≤ 9.0.89 | ≥ 8.5.35, ≤ 8.5.100 | ≥ 7.0.92, ≤ 7.0.109

  • UnknownTomcat

    ≥ 9.0.13, < 9.0.90 | ≥ 10.1.1, < 10.1.25 | 10.1.0:milestone1 | 10.1.0:milestone10 | 10.1.0:milestone11 | 10.1.0:milestone12 | 10.1.0:milestone13 | 10.1.0:milestone14 | 10.1.0:milestone15 | 10.1.0:milestone16 | 10.1.0:milestone17 | 10.1.0:milestone18 | 10.1.0:milestone19 | 10.1.0:milestone2 | 10.1.0:milestone20 | 10.1.0:milestone3 | 10.1.0:milestone4 | 10.1.0:milestone5 | 10.1.0:milestone6 | 10.1.0:milestone7 | 10.1.0:milestone8 | 10.1.0:milestone9 | 11.0.0:milestone1 | 11.0.0:milestone10 | 11.0.0:milestone11 | 11.0.0:milestone12 | 11.0.0:milestone13 | 11.0.0:milestone14 | 11.0.0:milestone15 | 11.0.0:milestone16 | 11.0.0:milestone17 | 11.0.0:milestone18 | 11.0.0:milestone19 | 11.0.0:milestone2 | 11.0.0:milestone20 | 11.0.0:milestone3 | 11.0.0:milestone4 | 11.0.0:milestone5 | 11.0.0:milestone6 | 11.0.0:milestone7 | 11.0.0:milestone8 | 11.0.0:milestone9

  • org.apache.tomcattomcat-util

    ≥ 11.0.0-M1, < 11.0.0-M21 | ≥ 10.1.0-M1, < 10.1.25 | ≥ 9.0.13, < 9.0.90 | ≥ 8.5.35, ≤ 8.5.100 | ≥ 7.0.92, ≤ 7.0.109

  • netappontap_tools

    9 | 10

References (10)