Vulnerability Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | >= 9.0.13, < 9.0.90 |
| Netapp | Ontap Tools | 9 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/wms60cvbsz3fpbz9psxtfx8r41jl6d4sMailing List
- http://www.openwall.com/lists/oss-security/2024/09/23/2Mailing List
- https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html
- https://security.netapp.com/advisory/ntap-20241101-0010/Third Party Advisory
FAQ
What is CVE-2024-38286?
CVE-2024-38286 is a vulnerability with a CVSS score of 8.6 (HIGH). Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 t...
How severe is CVE-2024-38286?
CVE-2024-38286 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-38286?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Netapp Ontap Tools.