Cross-site scripting in Apache Tomcat - CVE-2022-34305

 

Cross-site scripting in Apache Tomcat - CVE-2022-34305

Published: June 23, 2022 / Updated: June 26, 2022


Vulnerability identifier: #VU64627
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2022-34305
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data passed to the form authentication example in the examples web application. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Apache Tomcat
Gentoo Linux
Oracle Solaris
Traffix SDC
IBM App Connect Professional
RecoverPoint Classic
Oracle Communications User Data Repository
Dell Policy Manager for Secure Connect Gateway (SCG)
UrbanCode Build
Oracle Utilities Testing Accelerator
Cloudera Data Platform Private Cloud Base for IBM
Oracle Managed File Transfer
IBM UrbanCode Release
IBM Rational Build Forge
Oracle Communications Diameter Signaling Router
Oracle Communications Session Report Manager
Management Cloud Engine
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM Sterling Control Center
EMC NetWorker Server
MySQL Enterprise Monitor
Oracle Hospitality Cruise Shipboard Property Management System
Siebel UI Framework
Tomcat
Dell EMC Storage Monitoring and Reporting (SMR)
Communications Unified Assurance
RecoverPoint for VMs

How to mitigate CVE-2022-34305

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.82, 9.0.65, 10.0.23, 10.1.0-M17
RecoverPoint Classic - update to 5.1 SP4 P4
IBM UrbanCode Release - update to 6.2.5.8
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
IBM Rational Build Forge - update to 8.0.0.24
Tomcat - update to D.9.0.87.01
Netcool Operations Insight - update to 1.6.9
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.5.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
Communications Unified Assurance - update to 5.5.7
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.14.00.14
RecoverPoint for VMs - update to 6.0.SP1.P1
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
UrbanCode Build - update to 6.1.7.7
IBM Sterling Control Center - update to 6.2.1.0.14
EMC NetWorker Server - update to 19.7.0.2

External References

Related Security Bulletins