Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.8
- >= 10.1.0-M1, <= 10.1.42
- >= 9.0.0.M1, <= 9.0.106
A denial-of-service vulnerability has been identified in Apache Tomcat versions 11.0.0-M1 prior to 11.0.8, 10.1.0-M1 prior to 10.1.42, and 9.0.0-M1 prior to 9.0.106. This vulnerability arises from uncontrolled resource consumption when an HTTP/2 client fails to acknowledge the initial settings frame that limits the maximum allowed concurrent streams.
Exploitation of this vulnerability can lead to uncontrolled resource consumption, causing a denial-of-service condition on the server.
Users are advised to upgrade to Apache Tomcat 11.0.9, 10.1.43, or 9.0.107.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.