Allocation of Resources Without Limits or Throttling Affecting tomcat9 package, versions <9.0.70-2ubuntu0.1+esm2


Severity

Recommended
medium

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.69% (71st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UBUNTU2404-TOMCAT9-8097122
  • published14 Jun 2025
  • disclosed7 Nov 2024

Introduced: 7 Nov 2024

CVE-2024-38286  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade Ubuntu:24.04 tomcat9 to version 9.0.70-2ubuntu0.1+esm2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream tomcat9 package and not the tomcat9 package as distributed by Ubuntu. See How to fix? for Ubuntu:24.04 relevant fixed versions and status.

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. Older, unsupported versions may also be affected.

Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.

Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.

CVSS Base Scores

version 3.1