Data Handling in Apache Tomcat - CVE-2022-29885

 

Data Handling in Apache Tomcat - CVE-2022-29885

Published: May 16, 2022 / Updated: October 25, 2024


Vulnerability identifier: #VU63225
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29885
CWE-ID: CWE-19
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack.

The vulnerability exists due to an error in documentation for the EncryptInterceptor, which incorrectly stated that it enabled Tomcat clustering to run over an untrusted network. A remote attacker can perform a denial of service attack against the exposed EncryptInterceptor.


Affected software

Apache Tomcat
Debian Linux
Amazon Linux AMI
Oracle Solaris
Ubuntu
Dell Secure Connect Gateway
IBM UrbanCode Release
IBM Rational Build Forge
IBM Sterling Control Center
RecoverPoint Classic
IBM Engineering Requirements Management DOORS Next
Storage Copy Data Management
Storage Protect Plus Server
CloudBoost Virtual Appliance
IBM Qradar SIEM
Oracle Communications Element Manager
Oracle Agile PLM Framework
Oracle Hospitality Cruise Shipboard Property Management System
tomcat9 (Ubuntu package)
libtomcat9-java (Ubuntu package)
libtomcat8-java (Ubuntu package)
tomcat8 (Ubuntu package)
tomcat9-docs (Ubuntu package)
tomcat8-docs (Ubuntu package)
Tomcat
tomcat8
tomcat9 (Debian package)
Dell EMC Storage Monitoring and Reporting (SMR)
RecoverPoint for VMs

How to mitigate CVE-2022-29885

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.79, 9.0.63, 10.0.21, 10.1.0-M15
Dell Secure Connect Gateway - addressed in versions 5.14.00.10, 5.20.00.10
RecoverPoint Classic - update to 5.1 SP4 P4
IBM UrbanCode Release - update to 6.1.7.5
IBM Rational Build Forge - update to 8.0.0.23
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
tomcat9 (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
libtomcat9-java (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
libtomcat8-java (Ubuntu package) - update to Ubuntu Pro
tomcat8 (Ubuntu package) - update to Ubuntu Pro
tomcat9-docs (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
tomcat8-docs (Ubuntu package) - update to Ubuntu Pro
Tomcat - update to D.9.0.87.01
Storage Copy Data Management - update to 2.2.23.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
RecoverPoint for VMs - update to 6.0.SP1.P1
IBM Sterling Control Center - update to 6.2.1.0.14
tomcat8 - update to 8.5.81-1.91
tomcat9 (Debian package) - update to 9.0.43-2~deb11u4
Storage Protect Plus Server - update to 10.1.16.1
CloudBoost Virtual Appliance - update to 19.12.0.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins