Inconsistent interpretation of HTTP requests in Apache Tomcat - CVE-2022-42252

 

Inconsistent interpretation of HTTP requests in Apache Tomcat - CVE-2022-42252

Published: October 31, 2022 / Updated: July 9, 2024


Vulnerability identifier: #VU68859
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-42252
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers via an invalid Content-Length header.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks but requires Tomcat to be configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (not the default configuration).


Affected software

Apache Tomcat
JBoss Web Server
Confluence Server
Amazon Linux AMI
Gentoo Linux
Debian Linux
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
Ubuntu
openEuler
IBM Data Risk Manager
Oracle Financial Services Crime and Compliance Management Studio
SecureTransport
Communications Unified Assurance
Oracle Communications Instant Messaging Server
Dell Secure Connect Gateway
IBM UrbanCode Release
Confluence Data Center
IBM Rational Build Forge
Oracle Financial Services Model Management and Governance
Oracle Communications Diameter Signaling Router
Jira Software Data Center
Management Cloud Engine
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
IBM Process Mining
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Control Center
UCD - IBM UrbanCode Deploy
EMC NetWorker Server
MySQL Enterprise Monitor
Oracle Agile PLM Framework
Jira Software Server
IBM Qradar SIEM
IBM Engineering Requirements Management DOORS Next
Oracle Siebel CRM
Storage Copy Data Management
Dell Policy Manager for Secure Connect Gateway (SCG)
UrbanCode Build
CloudBoost Virtual Appliance
Oracle Communications Cloud Native Core Policy
tomcat8 (Ubuntu package)
libtomcat8-java (Ubuntu package)
tomcat9 (Ubuntu package)
libtomcat9-java (Ubuntu package)
Tomcat
tomcat-jsp-2_3-api
tomcat-lib
tomcat
tomcat-javadoc
tomcat-webapps
tomcat-servlet-3_1-api
tomcat-admin-webapps
tomcat-el-3_0-api
tomcat-docs-webapp
tomcat-jsvc
tomcat-help
tomcat-servlet-4_0-api
tomcat9 (Debian package)
jws5-tomcat (Red Hat package)
tomcat9
www-servers/tomcat
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
RecoverPoint for VMs
IBM Security SOAR

How to mitigate CVE-2022-42252

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.83, 9.0.68, 10.0.27, 10.1.1
IBM Data Risk Manager - update to 2.0.6.15
SecureTransport - update to 5.5-20221124
JBoss Web Server - update to 5.7.2
Dell Secure Connect Gateway - update to 5.16
IBM UrbanCode Release - update to 6.2.5.8
Confluence Server - update to 7.19.16
Confluence Data Center - update to 7.19.16
IBM Rational Build Forge - update to 8.0.0.24
Jira Software Server - update to 9.4.12
Jira Software Data Center - update to 9.4.12
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Oracle Siebel CRM - update to 23.3
tomcat8 (Ubuntu package) - update to Ubuntu Pro
libtomcat8-java (Ubuntu package) - update to Ubuntu Pro
tomcat9 (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.5
libtomcat9-java (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.5
Tomcat - update to D.9.0.87.01
Netcool Operations Insight - update to 1.6.9
IBM Process Mining - update to 1.13.2
Storage Copy Data Management - update to 2.2.23.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.5
EMC ViPR SRM - update to 4.8.0.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.1
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.14.00.14
RecoverPoint for VMs - update to 6.0.SP1.P1
UrbanCode Build - update to 6.1.7.7
IBM Sterling Control Center - update to 6.2.1.0.14
UCD - IBM UrbanCode Deploy - addressed in versions 6.2.7.19, 7.0.5.14, 7.1.2.10, 7.2.3.3, 7.3.0.1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
tomcat-jsp-2_3-api - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-lib - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-javadoc - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1
tomcat-webapps - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-servlet-3_1-api - update to 8.0.53-29.57.1
tomcat-admin-webapps - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-el-3_0-api - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-docs-webapp - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1
tomcat-jsvc - update to 9.0.10-27
tomcat - update to 9.0.10-27
tomcat-help - update to 9.0.10-27
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat9 (Debian package) - update to 9.0.43-2~deb11u6
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-13.redhat_00011.1.el7jws, 9.0.62-13.redhat_00011.1.el8jws, 9.0.62-13.redhat_00011.1.el9jws
tomcat9 - update to 9.0.71-1
www-servers/tomcat - update to 10.1.8
EMC NetWorker Server - update to 19.7.0.3
CloudBoost Virtual Appliance - update to 19.12.0.1
IBM Security SOAR - update to 47.1

External References

Related Security Bulletins