VDB
CVE-2024-50379
CVE-2024-50379
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case-insensitive file systems when the default servlet is enabled for write (non-default configuration)
EPSS 44.31% · 98.6th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
EPSS Score
44.31%
98.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ABB | B&R Industrial Automation GmbH APROL <R 4.4-01P5 |
Timeline
- CVE Published
- Dec 18, 2024 EPSS Score
- Jan 20, 2025 Coalition ESS Score
- Jan 27, 2025 PoC Published
- Mar 10, 2025 Coalition ESS Score
- Mar 17, 2025 EPSS Score
- Mar 18, 2025 Coalition ESS Score
- Mar 21, 2025 Coalition ESS Score
- Apr 2, 2025 Coalition ESS Score
- Apr 9, 2025 EPSS Score
- Apr 28, 2025 EPSS Score
- Apr 29, 2025 Coalition ESS Score
References
- https://psirt.abb.com/csaf/2026/sa26p011.json advisory
- https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P011-661853b7.pdf advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-50379 advisory
- https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf advisory