CVE-2024-54677
MEDIUMApache Tomcat 8.5.0-8.5.100, 9.0.0.M1-9.0.97, 10.1.0-M1-10.1.33, 11.0.0-M1-11.0.1 - DoS via Examples Web App
Title source: llmDescription
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
References (6)
Core 6
Core References
Third Party Advisory
https://security.netapp.com/advisory/ntap-20250131-0006/
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/tdtbbxpg5trdwc2wnopcth9ccvdftq2n
Scores
CVSS v3
5.3
EPSS
0.0123
EPSS Percentile
79.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (6)
apache/tomcat
9.0.0 - 9.0.98
netapp/bootstrap_os
org.apache.tomcat/tomcat
10.1.0-M1 - 10.1.34Maven
org.apache.tomcat/tomcat
11.0.0-M1 - 11.0.2Maven
org.apache.tomcat/tomcat
9.0.0.M1 - 9.0.98Maven
org.apache.tomcat/tomcat-catalina
8.5.0 - 8.5.100Maven
Published
Dec 17, 2024
Tracked Since
Feb 18, 2026