Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.9
- >= 10.1.0-M1, <= 10.1.43
- >= 9.0.0.M1, <= 9.0.107
A denial-of-service vulnerability has been identified in Apache Tomcat's HTTP/2 implementation, affecting versions 11.0.0-M1 prior to 11.0.9, 10.1.0-M1 prior to 10.1.43, and 9.0.0-M1 prior to 9.0.107. This vulnerability is susceptible to the 'made you reset' attack, which can lead to an OutOfMemoryError. Older, end-of-life versions may also be affected.
Exploitation of this vulnerability causes a denial-of-service condition, typically resulting in an OutOfMemoryError.
Users should upgrade to Apache Tomcat 11.0.10 or later, 10.1.44 or later, or 9.0.108 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.