CVE-2024-38286
published 2024-11-07CVE-2024-38286: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.70%
74.6th percentile
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.
Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.1 < 10.1.25 | 10.1.25 |
| apache | tomcat | >= 9.0.13 < 9.0.90 | 9.0.90 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.24 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.0-M20 | — |
| apache_software_foundation | apache_tomcat | 7.0.92 – 7.0.109 | — |
| apache_software_foundation | apache_tomcat | 8.5.35 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.13 – 9.0.89 | — |
| atlassian | crowd | — | — |
| debian | tomcat10 | < tomcat10 10.1.34-0+deb12u1 (bookworm) | tomcat10 10.1.34-0+deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.34-0+deb12u1 (bookworm) | tomcat10 10.1.34-0+deb12u1 (bookworm) |
| netapp | ontap_tools | — | — |
| netapp | ontap_tools | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tomcat vulnerabilities
osv·2025-06-09·CVSS 4.3
CVE-2023-28708 [MEDIUM] tomcat vulnerabilities
tomcat vulnerabilities
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-42795)
It was discovered that Tomcat incorrectly handled HTTP
t
GHSA
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
ghsa·2024-11-07
CVE-2024-38286 [HIGH] CWE-770 Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109.
Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.
Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
OSV
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
osv·2024-11-07
CVE-2024-38286 [HIGH] Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109.
Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.
Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
OSV
CVE-2024-38286: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat
osv·2024-11-07·CVSS 7.5
CVE-2024-38286 [HIGH] CVE-2024-38286: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2025-06-09·CVSS 4.3
CVE-2024-34750 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in tomcat8, tomcat9, tomcat10.
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubunt
Atlassian
CVE-2024-38286: 6.1.1 to 6.1.2 recommended Data Center Only 6.0.3 to 6.0.4 Data Center Only 5.3.6 Data Center Only
vendor_atlassian·2024-11-19·CVSS 6.0
CVE-2024-38286 [HIGH] CVE-2024-38286: 6.1.1 to 6.1.2 recommended Data Center Only 6.0.3 to 6.0.4 Data Center Only 5.3.6 Data Center Only
CVE-2024-38286: 6.1.1 to 6.1.2 recommended Data Center Only 6.0.3 to 6.0.4 Data Center Only 5.3.6 Data Center Only
6.1.1 to 6.1.2 recommended Data Center Only 6.0.3 to 6.0.4 Data Center Only 5.3.6 Data Center Only
CVE: CVE-2024-38286
Affected products: Crowd
Red Hat
tomcat: Denial of Service in Tomcat
vendor_redhat·2024-09-23·CVSS 8.6
CVE-2024-38286 [HIGH] CWE-400 tomcat: Denial of Service in Tomcat
tomcat: Denial of Service in Tomcat
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.
Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
A vulnerability was found in Tomcat. Under certain configurations on any platform, this flaw allows an attacker to c
Debian
CVE-2024-38286: tomcat10 - Allocation of Resources Without Limits or Throttling vulnerability in Apache Tom...
vendor_debian·2024·CVSS 8.6
CVE-2024-38286 [HIGH] CVE-2024-38286: tomcat10 - Allocation of Resources Without Limits or Throttling vulnerability in Apache Tom...
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
Scope: local
bookworm: resolved (fixed in 10.1.34-0+deb12u1)
forky: resolved (fixed in 10.1.25-1)
sid: resolved (fixed in 10.1.25-1)
trixie: resolved (fix
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-07
Published