PT-2024-6592 · Apache+9 · Apache Tomcat+9

·

CVE-2024-38286

·

Published

2024-06-19

·

Updated

2026-08-03

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions:
Apache Tomcat versions 9.0.13 through 9.0.89, 10.1.0-M1 through 10.1.24, and 11.0.0-M1 through 11.0.0-M20. Older, End-of-Life (EOL) versions including 7.0.92 through 7.0.109 and 8.5.35 through 8.5.100 are also affected.
Description:
A vulnerability exists in Apache Tomcat that allows an attacker to cause a denial-of-service (DoS) condition by abusing the TLS handshake process, potentially leading to an OutOfMemoryError. This issue occurs under certain configurations on any platform.
Recommendations:
Apache Tomcat versions prior to 11.0.0-M21 are affected. Upgrade to version 11.0.0-M21 or later. Apache Tomcat versions prior to 10.1.25 are affected. Upgrade to version 10.1.25 or later. Apache Tomcat versions prior to 9.0.90 are affected. Upgrade to version 9.0.90 or later.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-1726
ALT-PU-2025-2379
ALT-PU-2025-9146
BDU:2024-07738
BIT-TOMCAT-2024-38286
CESA-2024_5694
CVE-2024-38286
DLA-4017-1
DSA-5845-1
GHSA-7JQF-V358-P8G7
RHSA-2024:4976
RHSA-2024:5024
RHSA-2024:5693
RHSA-2024:5694
RHSA-2024:5695
RHSA-2024:5696
RHSA-2024:8494
RHSA-2024:8497
RHSA-2024:8528
RHSA-2024:8543
RHSA-2024:8567
RHSA-2024:8572
RHSA-2024_5693
RHSA-2024_5694
SUSE-SU-2024:3510-1
SUSE-SU-2024_3510-1
SUSE-SU-2026:1058-1
USN-7562-1

Affected Products

Alt Linux
Apache Tomcat
Astra Linux
Bitbucket
Centos
Linuxmint
Red Hat
Red Os
Suse
Ubuntu