CVE-2024-38286

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Nov 7, 2024
Updated: Nov 8, 2024
CWE ID 770

Summary

CVE-2024-38286 is a resource exhaustion vulnerability affecting multiple versions of Apache Tomcat, including 11.0.0-M1 through 11.0.0-M20, 10.1.0-M1 through 10.1.24, and 9.0.13 through 9.0.89. This issue arises when an attacker manipulates the TLS handshake process, leading to an OutOfMemoryError in Apache Tomcat. To mitigate this vulnerability, users are advised to upgrade to the latest versions, specifically 11.0.0-M21, 10.1.25, or 9.0.90. Older, unsupported versions may also be susceptible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Apache Tomcat

Affected Vendors

  • Apache Software Foundation