PT-2024-9810 · Apache+8 · Apache Tomcat+8

Nacl

+3

·

Published

2024-12-09

·

Updated

2026-05-29

·

CVE-2024-56337

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Apache Tomcat versions 9.0.0-M1 through 11.0.1
Description: The issue is a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that can be exploited to bypass case sensitivity checks and execute arbitrary code. This can be done by uploading a file that can be turned into malicious JSP code, resulting in remote code execution. The exploit can be carried out on case-insensitive file systems where Tomcat's default servlet has write functionality enabled. Over 894,000 Apache Tomcat applications are potentially vulnerable to this exploit. A proof-of-concept has been released, and it is expected that more exploitation will occur.
Recommendations: Update to patched versions of Apache Tomcat and adjust Java configuration accordingly to prevent remote code execution. As a temporary workaround, consider disabling the default servlet's write functionality on case-insensitive file systems to minimize the risk of exploitation. Restrict access to the vulnerable jsp files to prevent malicious code execution until the issue is resolved.

Fix

RCE

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:11332
ALSA-2025:11333
ALSA-2025:11335
ALT-PU-2025-1726
ALT-PU-2025-2379
BDU:2024-11586
BIT-TOMCAT-2024-56337
CESA-2025_11333
CVE-2024-56337
DLA-4017-1
DSA-5845-1
GHSA-27HP-XHWR-WR2M
INFSA-2025_11333
INFSA-2025_11335
OESA-2025-1226
OPENSUSE-SU-2025:14896-1
OPENSUSE-SU-2025:14897-1
OPENSUSE-SU-2025_1024-1
OPENSUSE-SU-2025_1126-1
RHSA-2025:11332
RHSA-2025:11333
RHSA-2025:11334
RHSA-2025:11335
RHSA-2025:11381
RHSA-2025:11382
RHSA-2025:4521
RHSA-2025_11333
RHSA-2025_11335
SUSE-SU-2025:0033-1
SUSE-SU-2025:0058-1
SUSE-SU-2025:1024-1
SUSE-SU-2025:1126-1
SUSE-SU-2025_1024-1
SUSE-SU-2025_1126-1

Affected Products

Alt Linux
Almalinux
Apache Tomcat
Centos
Confluence
Red Hat
Red Os
Rocky Linux
Suse