Security restrictions bypass in Apache Tomcat - CVE-2022-23181

 

Security restrictions bypass in Apache Tomcat - CVE-2022-23181

Published: January 27, 2022 / Updated: January 28, 2022


Vulnerability identifier: #VU60079
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23181
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a time of check, time of use flaw when configured to persist sessions using the FileStore. A local user can perform certain actions which lead to security restrictions bypass and privilege escalation (code execution with Tomcat process privileges).


Affected software

Apache Tomcat
JBoss Web Server
Amazon Linux AMI
Debian Linux
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Ubuntu
openEuler
Fedora
Red Hat Openshift Application Runtimes
IBM Process Mining
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
Oracle Financial Services Model Management and Governance
IBM Sterling Control Center
EMC NetWorker Server
Oracle Communications Cloud Native Core Policy
RecoverPoint Classic
Oracle Retail Xstore Point of Service
CloudBoost Virtual Appliance
SecureTransport
MySQL Enterprise Monitor
Oracle Financial Services Crime and Compliance Management Studio
Oracle Communications Instant Messaging Server
tomcat8-docs (Ubuntu package)
tomcat8 (Ubuntu package)
libtomcat8-java (Ubuntu package)
tomcat9 (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9-docs (Ubuntu package)
Tomcat
jws5 (Red Hat package)
jws5-javapackages-tools (Red Hat package)
tomcat-help
tomcat-jsvc
tomcat
tomcat-admin-webapps
tomcat-jsp-2_3-api
tomcat-webapps
tomcat-servlet-4_0-api
tomcat-lib
tomcat-el-3_0-api
tomcat9 (Debian package)
tomcat9

How to mitigate CVE-2022-23181

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.75, 9.0.58, 10.0.15, 10.1.0-M10
IBM Process Mining - update to 1.12.0.4
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.7
JBoss Web Server - update to 5.7.0
Dell Secure Connect Gateway - update to 5.14.00.10
RecoverPoint Classic - update to 5.1 SP4 P4
SecureTransport - update to 5.5-20220224
tomcat8-docs (Ubuntu package) - update to Ubuntu Pro
tomcat8 (Ubuntu package) - update to Ubuntu Pro
libtomcat8-java (Ubuntu package) - update to Ubuntu Pro
tomcat9 (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
libtomcat9-java (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
tomcat9-docs (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
Tomcat - update to D.9.0.87.01
jws5 (Red Hat package) - update to 1-8.el9jws
jws5-javapackages-tools (Red Hat package) - update to 3.4.1-5.15.11.el9jws
IBM Sterling Control Center - update to 6.2.1.0.14
tomcat-help - addressed in versions 9.0.10-25, 9.0.10-26
tomcat-jsvc - addressed in versions 9.0.10-25, 9.0.10-26
tomcat - addressed in versions 9.0.10-25, 9.0.10-26
tomcat-admin-webapps - addressed in versions 9.0.36-3.90.1, 9.0.36-4.70.1
tomcat - addressed in versions 9.0.36-3.90.1, 9.0.36-4.70.1
tomcat-jsp-2_3-api - addressed in versions 9.0.36-3.90.1, 9.0.36-4.70.1
tomcat-webapps - addressed in versions 9.0.36-3.90.1, 9.0.36-4.70.1
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.90.1, 9.0.36-4.70.1
tomcat-lib - addressed in versions 9.0.36-3.90.1, 9.0.36-4.70.1
tomcat-el-3_0-api - addressed in versions 9.0.36-3.90.1, 9.0.36-4.70.1
tomcat9 (Debian package) - update to 9.0.43-2~deb11u4
tomcat - update to 9.0.59-1.fc37
tomcat9 - update to 9.0.64-1
EMC NetWorker Server - update to 19.7.0.0
CloudBoost Virtual Appliance - update to 19.12.0.1

External References

Related Security Bulletins