Cyber Security News

Apache Tomcat Vulnerability Lets Attackers Trigger Dos Attack

A newly discovered vulnerability in Apache Tomcat, CVE-2024-38286, has raised significant concerns among cybersecurity experts.

This flaw allows attackers to trigger a Denial of Service (DoS) attack by exploiting the TLS handshake process.

The vulnerability, classified as “Important” in severity, affects several versions of Apache Tomcat. Here is a table summarizing the affected versions of Apache Tomcat due to the CVE-2024-38286 vulnerability:

Apache Tomcat VersionAffected Versions
11.0.x11.0.0-M1 to 11.0.0-M20
10.1.x10.1.0-M1 to 10.1.24
9.0.x9.0.13 to 9.0.89

The Apache Software Foundation, the vendor behind Tomcat, has confirmed that an attacker can cause an OutOfMemoryError by abusing the TLS handshake process under specific configurations on any platform.

This can lead to a Denial of Service condition, severely impacting the availability and performance of applications relying on affected Tomcat versions.

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Free Registration

Mitigation Measures Urged

In response to the discovery, the Apache Software Foundation has urged users of affected versions to take immediate action to mitigate the risk.

The recommended solutions include upgrading to the latest secure versions: Apache Tomcat 11.0.0-M21 or later, 10.1.25 or later, and 9.0.90 or later.

Organizations using Apache Tomcat are advised to review their current configurations and apply the necessary updates promptly to protect their systems from potential exploits.

Ozaki from North Grid Corporation responsibly reported the vulnerability, highlighting the importance of collaboration between researchers and software vendors in identifying and addressing security issues.

The Apache Software Foundation has expressed gratitude for the responsible disclosure and has emphasized its commitment to maintaining the security and reliability of its software products.

As Apache Tomcat is widely used in enterprise environments for running Java applications, this vulnerability underscores the critical need for regular security assessments and timely updates in software management practices.

By staying informed and proactive in applying security patches, businesses can safeguard their systems from disruptions caused by such vulnerabilities.

Analyse AnySuspicious Links Using ANY.RUN's New Safe Browsing Tool: Try It for Free

Dhivya

Divya is a Senior Journalist at Cyber Security news covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago