A recently discovered vulnerability in Apache Tomcat, identified as CVE-2024-38286 , has raised significant concerns among cybersecurity experts , as it allows for DoS attacks .
See also: Atlassian patches multiple high-severity vulnerabilities

This flaw allows attackers to trigger a denial of service (DoS) attack by exploiting the TLS handshake.
The vulnerability, classified as high severity, affects several Apache Tomcat versions.
The Apache Software Foundation, the vendor behind the Tomcat software, has confirmed that an attacker can cause an OutOfMemoryError by abusing the TLS handshake process under certain configurations on any platform and perform DoS attacks. This can seriously impact the availability and performance of applications based on the affected Tomcat versions.
In response to the discovery, the Apache Software Foundation urged users of affected versions to take immediate steps to mitigate the risk.
Recommended solutions include upgrading to the latest secure versions: Apache Tomcat 11.0.0-M21 or later, 10.1.25 or later, and 9.0.90 or later.
See also: Vulnerability in Cisco IOS XR allows hackers to gain elevated privileges
Organizations using Apache Tomcat are advised to review their current configurations and apply the necessary updates immediately to protect their systems from potential exploits.

Ozaki from North Grid Corporation responsibly reported the vulnerability, highlighting the importance of collaboration between researchers and software vendors to identify and address security issues. The Apache Software Foundation has expressed its gratitude for the responsible disclosure and has emphasized its commitment to maintaining the security and reliability of its software products.
As Apache Tomcat is widely used in enterprise environments to run Java, this vulnerability, which could allow DoS attacks, highlights the critical need for regular security assessments and timely updates to software management practices.
By staying up-to-date and proactive when applying security patches, businesses can protect their systems from outages caused by such vulnerabilities.
See also: Cyberattack in Columbus city under investigation by federal authorities
Denial of Service (DoS) attacks are malicious attempts to disrupt the normal operation of a service, server, or network, making it unavailable to its users. This is achieved by overloading the system with excessive traffic or access attempts that exceed the system's management capabilities. DoS attacks can have a serious impact on businesses and organizations, as they can cause revenue loss, reputation damage, and data loss. While countering these attacks is a challenge, there are security measures that can be taken to enhance the resilience of a system.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
