Data Handling in Apache Tomcat - CVE-2022-29885
Published: May 16, 2022 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack.
The vulnerability exists due to an error in documentation for the EncryptInterceptor, which incorrectly stated that it enabled Tomcat clustering to run over an untrusted network. A remote attacker can perform a denial of service attack against the exposed EncryptInterceptor.
Affected software
Debian Linux
Amazon Linux AMI
Oracle Solaris
Ubuntu
Dell Secure Connect Gateway
IBM UrbanCode Release
IBM Rational Build Forge
IBM Sterling Control Center
RecoverPoint Classic
IBM Engineering Requirements Management DOORS Next
Storage Copy Data Management
Storage Protect Plus Server
CloudBoost Virtual Appliance
IBM Qradar SIEM
Oracle Communications Element Manager
Oracle Agile PLM Framework
Oracle Hospitality Cruise Shipboard Property Management System
tomcat9 (Ubuntu package)
libtomcat9-java (Ubuntu package)
libtomcat8-java (Ubuntu package)
tomcat8 (Ubuntu package)
tomcat9-docs (Ubuntu package)
tomcat8-docs (Ubuntu package)
Tomcat
tomcat8
tomcat9 (Debian package)
Dell EMC Storage Monitoring and Reporting (SMR)
RecoverPoint for VMs
How to mitigate CVE-2022-29885
Dell Secure Connect Gateway - addressed in versions 5.14.00.10, 5.20.00.10
RecoverPoint Classic - update to 5.1 SP4 P4
IBM UrbanCode Release - update to 6.1.7.5
IBM Rational Build Forge - update to 8.0.0.23
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
tomcat9 (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
libtomcat9-java (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
libtomcat8-java (Ubuntu package) - update to Ubuntu Pro
tomcat8 (Ubuntu package) - update to Ubuntu Pro
tomcat9-docs (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
tomcat8-docs (Ubuntu package) - update to Ubuntu Pro
Tomcat - update to D.9.0.87.01
Storage Copy Data Management - update to 2.2.23.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
RecoverPoint for VMs - update to 6.0.SP1.P1
IBM Sterling Control Center - update to 6.2.1.0.14
tomcat8 - update to 8.5.81-1.91
tomcat9 (Debian package) - update to 9.0.43-2~deb11u4
Storage Protect Plus Server - update to 10.1.16.1
CloudBoost Virtual Appliance - update to 19.12.0.1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Denial of service in Apache Tomcat
- Data Handling in Oracle Hospitality Cruise Shipboard Property Management System
- Denial of service in IBM UrbanCode Build
- Denial of service in IBM Rational Build Forge
- Amazon Linux AMI update for tomcat8
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Oracle Communications Element Manager
- Multiple vulnerabilities in Oracle Agile PLM Framework
- Oracle Solaris update for third-party software
- Multiple vulnerabilities in IBM QRadar SIEM
- Debian update for tomcat9
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell RecoverPoint Classic
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Multiple vulnerabilities in IBM Storage Protect Plus Server
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Ubuntu update for tomcat8
- HP-UX update for Tomcat
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Dell CloudBoost Virtual Appliance update for third-party components