Back

MEDIUM

Apache Tomcat: DoS in examples web application

Published Dec 17, 2024

Description

Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.

Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

Affected products

Remediation

Red Hat statement

By default, the examples web application is only accessible to the localhost.

References (36)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Dec 17, 2024
Updated Nov 3, 2025
Reserved Dec 5, 2024
CISA Vulnrichment
Updated Dec 17, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 17, 2024
GHSA-653P-VG55-5652