7.5

CVE-2024-38286

Apache Tomcat: Denial of Service

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89.


The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected.


Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.



Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 9.0.13 < 9.0.90
Apache ≫ Tomcat Version >= 10.1.1 < 10.1.25
Apache ≫ Tomcat Version 10.1.0 Update milestone1
Apache ≫ Tomcat Version 10.1.0 Update milestone10
Apache ≫ Tomcat Version 10.1.0 Update milestone11
Apache ≫ Tomcat Version 10.1.0 Update milestone12
Apache ≫ Tomcat Version 10.1.0 Update milestone13
Apache ≫ Tomcat Version 10.1.0 Update milestone14
Apache ≫ Tomcat Version 10.1.0 Update milestone15
Apache ≫ Tomcat Version 10.1.0 Update milestone16
Apache ≫ Tomcat Version 10.1.0 Update milestone17
Apache ≫ Tomcat Version 10.1.0 Update milestone18
Apache ≫ Tomcat Version 10.1.0 Update milestone19
Apache ≫ Tomcat Version 10.1.0 Update milestone2
Apache ≫ Tomcat Version 10.1.0 Update milestone20
Apache ≫ Tomcat Version 10.1.0 Update milestone3
Apache ≫ Tomcat Version 10.1.0 Update milestone4
Apache ≫ Tomcat Version 10.1.0 Update milestone5
Apache ≫ Tomcat Version 10.1.0 Update milestone6
Apache ≫ Tomcat Version 10.1.0 Update milestone7
Apache ≫ Tomcat Version 10.1.0 Update milestone8
Apache ≫ Tomcat Version 10.1.0 Update milestone9
Apache ≫ Tomcat Version 11.0.0 Update milestone1
Apache ≫ Tomcat Version 11.0.0 Update milestone10
Apache ≫ Tomcat Version 11.0.0 Update milestone11
Apache ≫ Tomcat Version 11.0.0 Update milestone12
Apache ≫ Tomcat Version 11.0.0 Update milestone13
Apache ≫ Tomcat Version 11.0.0 Update milestone14
Apache ≫ Tomcat Version 11.0.0 Update milestone15
Apache ≫ Tomcat Version 11.0.0 Update milestone16
Apache ≫ Tomcat Version 11.0.0 Update milestone17
Apache ≫ Tomcat Version 11.0.0 Update milestone18
Apache ≫ Tomcat Version 11.0.0 Update milestone19
Apache ≫ Tomcat Version 11.0.0 Update milestone2
Apache ≫ Tomcat Version 11.0.0 Update milestone20
Apache ≫ Tomcat Version 11.0.0 Update milestone3
Apache ≫ Tomcat Version 11.0.0 Update milestone4
Apache ≫ Tomcat Version 11.0.0 Update milestone5
Apache ≫ Tomcat Version 11.0.0 Update milestone6
Apache ≫ Tomcat Version 11.0.0 Update milestone7
Apache ≫ Tomcat Version 11.0.0 Update milestone8
Apache ≫ Tomcat Version 11.0.0 Update milestone9
Netapp ≫ Ontap Tools Version 9 SwPlatform vmware_vsphere
Netapp ≫ Ontap Tools Version 10 SwPlatform vmware_vsphere
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.69% 0.75
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Apache 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://lists.apache.org/thread/wms60cvbsz3fpbz9psxtfx8r41jl6d4s
Mailing List
http://www.openwall.com/lists/oss-security/2024/09/23/2
Mailing List
https://security.netapp.com/advisory/ntap-20241101-0010/
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html