Incorrect object recycling and reuse vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96.
Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | apache-tomcat-upgrade-9_0_97apache-tomcat-upgrade-10_1_33apache-tomcat-upgrade-11_0_1apache-tomcat-10_1apache-tomcat-11_0apache-tomcat-9_0apache-tomcat-upgrade-latest | Nov 19, 2024 | Nov 18, 2024 | |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Nov 18, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub