CVE-2024-38286
CVSS 3.1 Score 8.6 of 10 (high)
Details
Published Nov 7, 2024
Updated: Nov 8, 2024
CWE ID 770
Summary
CVE-2024-38286 is a resource exhaustion vulnerability affecting multiple versions of Apache Tomcat, including 11.0.0-M1 through 11.0.0-M20, 10.1.0-M1 through 10.1.24, and 9.0.13 through 9.0.89. This issue arises when an attacker manipulates the TLS handshake process, leading to an OutOfMemoryError in Apache Tomcat. To mitigate this vulnerability, users are advised to upgrade to the latest versions, specifically 11.0.0-M21, 10.1.25, or 9.0.90. Older, unsupported versions may also be susceptible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Apache Tomcat
Affected Vendors
- Apache Software Foundation