Article - CS414467

Apache Tomcat security vulnerabilities CVE-2024-23672 and CVE-2024-24549 in Windchill

Modified: 18-Jun-2024   


Applies To

  • Windchill PDMLink 11.1 to 13.0
  • FlexPLM 12.1

Description

  • The tomcat versions  used by Windchill are impacted by the following tomcat security vulnerabilities :
    • CVE-2024-23672 ( refer to  https://nvd.nist.gov/vuln/detail/CVE-2024-23672 ) 
      • Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.  Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
    • CVE-2024-24549  ( refer to  https://nvd.nist.gov/vuln/detail/CVE-2024-24549 )
    • Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
This is a printer-friendly version of Article 414467 and may be out of date. For the latest version click CS414467