VDB
CVE-2024-52317
CVE-2024-52317
PUBLISHED
CVSS 6.5 MEDIUM
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the re-quest and response used by HTTP/2 requests could lead to request and/or response mix-up between users
EPSS 2.10% · 80.4th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:H/RL:O/RC:C
EPSS Score
2.10%
80.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ABB | B&R Industrial Automation GmbH APROL <R 4.4-01P5 |
Timeline
- Nov 17, 2024 CVE Published
- Nov 18, 2024 Coalition ESS Score
- Nov 18, 2024 Coalition ESS Score
- Nov 19, 2024 EPSS Score
- Nov 19, 2024 Coalition ESS Score
- Dec 25, 2024 EPSS Score
- Jan 12, 2025 EPSS Score
- Feb 14, 2025 Coalition ESS Score
- Feb 16, 2025 EPSS Score
- Feb 26, 2025 Coalition ESS Score
- Mar 6, 2025 EPSS Score
- Mar 20, 2025 EPSS Score
References
- https://psirt.abb.com/csaf/2026/sa26p011.json advisory
- https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P011-661853b7.pdf advisory
- https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-52317 advisory