DLP Assessment - Apache Tomcat Remote DoS Vulnerability - CVE-2024-38286
search cancel

DLP Assessment - Apache Tomcat Remote DoS Vulnerability - CVE-2024-38286

book

Article ID: 378602

calendar_today

Updated On:

Products

Data Loss Prevention

Issue/Introduction

Need assessment for DLP on Apache Tomcat Remote DoS Vulnerability - CVE-2024-38286

Environment

DLP 16.x

Cause

CVE-2024-38286 Is a vulnerability to the TLS 1.3 handshake when TLS 1.3 is in use.

Resolution

DLP versions before 16.1 do not use TLS 1.3 as such are not impacted by this CVE.
DLP 16.1 which does use TLS 1.3 was released with Tomcat 9.0.90 which has this vulnerability resolved.