Error Handling in Apache Tomcat - CVE-2022-25762
Published: May 17, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an error when handling WebSocket connections. If a web application sends a WebSocket message concurrently with the
WebSocket connection closing, it is possible that the application will
continue to use the socket after it has been closed. As a result, subsequent connections can use the
same object concurrently and share data and/or other errors.
Affected software
Amazon Linux AMI
Oracle Solaris
openEuler
Traffix SDC
IBM UrbanCode Release
IBM Sterling Control Center
IBM Qradar SIEM
IBM Spectrum Virtualize
Oracle Agile PLM Framework
IBM Engineering Requirements Management DOORS Next
Storage Copy Data Management
Storage Protect Plus Server
tomcat8
tomcat
tomcat-jsvc
tomcat-help
How to mitigate CVE-2022-25762
IBM UrbanCode Release - update to 6.2.5.6
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Storage Copy Data Management - update to 2.2.23.0
IBM Sterling Control Center - update to 6.2.1.0.14
tomcat8 - update to 8.5.81-1.91
tomcat - addressed in versions 9.0.96-1, 9.0.96-2
tomcat-jsvc - addressed in versions 9.0.96-1, 9.0.96-2
tomcat-help - addressed in versions 9.0.96-1, 9.0.96-2
Storage Protect Plus Server - update to 10.1.16.1
External References
Related Security Bulletins
- Information disclosure in Apache Tomcat
- Information disclosure in Traffix SDC WebUI (Apache Tomcat component)
- Multiple vulnerabilities in Oracle Agile PLM Framework
- Multiple vulnerabilities in Oracle Solaris
- Information disclosure in IBM UrbanCode Release
- Amazon Linux AMI update for tomcat8
- Information disclosure in IBM Spectrum Virtualize
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Multiple vulnerabilities in IBM Storage Protect Plus Server
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Multiple vulnerabilities in IBM Control Center
- openEuler 22.03 LTS SP4 update for tomcat
- openEuler 22.03 LTS SP1 update for tomcat
- openEuler 20.03 LTS SP4 update for tomcat
- openEuler 22.03 LTS SP3 update for tomcat
- openEuler 24.03 LTS update for tomcat