Cross-site scripting in Apache Tomcat - CVE-2022-34305
Published: June 23, 2022 / Updated: June 26, 2022
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed to the form authentication example in the examples web application. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Gentoo Linux
Oracle Solaris
Traffix SDC
IBM App Connect Professional
RecoverPoint Classic
Oracle Communications User Data Repository
Dell Policy Manager for Secure Connect Gateway (SCG)
UrbanCode Build
Oracle Utilities Testing Accelerator
Cloudera Data Platform Private Cloud Base for IBM
Oracle Managed File Transfer
IBM UrbanCode Release
IBM Rational Build Forge
Oracle Communications Diameter Signaling Router
Oracle Communications Session Report Manager
Management Cloud Engine
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM Sterling Control Center
EMC NetWorker Server
MySQL Enterprise Monitor
Oracle Hospitality Cruise Shipboard Property Management System
Siebel UI Framework
Tomcat
Dell EMC Storage Monitoring and Reporting (SMR)
Communications Unified Assurance
RecoverPoint for VMs
How to mitigate CVE-2022-34305
RecoverPoint Classic - update to 5.1 SP4 P4
IBM UrbanCode Release - update to 6.2.5.8
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
IBM Rational Build Forge - update to 8.0.0.24
Tomcat - update to D.9.0.87.01
Netcool Operations Insight - update to 1.6.9
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.5.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
Communications Unified Assurance - update to 5.5.7
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.14.00.14
RecoverPoint for VMs - update to 6.0.SP1.P1
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
UrbanCode Build - update to 6.1.7.7
IBM Sterling Control Center - update to 6.2.1.0.14
EMC NetWorker Server - update to 19.7.0.2
External References
Related Security Bulletins
- XSS in Apache Tomcat
- XSS in Traffix SDC WebUI (Apache Tomcat component)
- XSS in IBM App Connect Professional
- Gentoo update for Apache Tomcat
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Cross-site scripting in Oracle Communications Session Report Manager
- Multiple vulnerabilities in Oracle Communications User Data Repository
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Oracle Hospitality Cruise Shipboard Property Management System
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in Oracle Utilities Testing Accelerator
- Multiple vulnerabilities in Siebel UI Framework
- Oracle Solaris update for third-party software
- Cross-site scripting in Dell NetWorker
- Cross-site scripting in IBM UrbanCode Build
- Cross-site scripting in IBM Sterling Partner Engagement Manager
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data update for Apache Tomcat
- Multiple vulnerabilities in Management Cloud Engine
- Cross-site scripting in IBM UrbanCode Release
- Multiple vulnerabilities in Dell Secure Connect Gateway Policy Manager
- Multiple vulnerabilities in Oracle Managed File Transfer
- Multiple vulnerabilities in Dell RecoverPoint Classic
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Rational Build Forge
- HP-UX update for Tomcat
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Multiple vulnerabilities in Cloudera Data Platform Private Cloud Base with IBM (CDP)