Inconsistent interpretation of HTTP requests in Apache Tomcat - CVE-2022-42252
Published: October 31, 2022 / Updated: July 9, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers via an invalid
Content-Length header.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks but requires Tomcat to be configured to ignore invalid HTTP headers via setting
rejectIllegalHeader to false (not the default configuration).
Affected software
JBoss Web Server
Confluence Server
Amazon Linux AMI
Gentoo Linux
Debian Linux
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
Ubuntu
openEuler
IBM Data Risk Manager
Oracle Financial Services Crime and Compliance Management Studio
SecureTransport
Communications Unified Assurance
Oracle Communications Instant Messaging Server
Dell Secure Connect Gateway
IBM UrbanCode Release
Confluence Data Center
IBM Rational Build Forge
Oracle Financial Services Model Management and Governance
Oracle Communications Diameter Signaling Router
Jira Software Data Center
Management Cloud Engine
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
IBM Process Mining
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Control Center
UCD - IBM UrbanCode Deploy
EMC NetWorker Server
MySQL Enterprise Monitor
Oracle Agile PLM Framework
Jira Software Server
IBM Qradar SIEM
IBM Engineering Requirements Management DOORS Next
Oracle Siebel CRM
Storage Copy Data Management
Dell Policy Manager for Secure Connect Gateway (SCG)
UrbanCode Build
CloudBoost Virtual Appliance
Oracle Communications Cloud Native Core Policy
tomcat8 (Ubuntu package)
libtomcat8-java (Ubuntu package)
tomcat9 (Ubuntu package)
libtomcat9-java (Ubuntu package)
Tomcat
tomcat-jsp-2_3-api
tomcat-lib
tomcat
tomcat-javadoc
tomcat-webapps
tomcat-servlet-3_1-api
tomcat-admin-webapps
tomcat-el-3_0-api
tomcat-docs-webapp
tomcat-jsvc
tomcat-help
tomcat-servlet-4_0-api
tomcat9 (Debian package)
jws5-tomcat (Red Hat package)
tomcat9
www-servers/tomcat
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
RecoverPoint for VMs
IBM Security SOAR
How to mitigate CVE-2022-42252
IBM Data Risk Manager - update to 2.0.6.15
SecureTransport - update to 5.5-20221124
JBoss Web Server - update to 5.7.2
Dell Secure Connect Gateway - update to 5.16
IBM UrbanCode Release - update to 6.2.5.8
Confluence Server - update to 7.19.16
Confluence Data Center - update to 7.19.16
IBM Rational Build Forge - update to 8.0.0.24
Jira Software Server - update to 9.4.12
Jira Software Data Center - update to 9.4.12
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Oracle Siebel CRM - update to 23.3
tomcat8 (Ubuntu package) - update to Ubuntu Pro
libtomcat8-java (Ubuntu package) - update to Ubuntu Pro
tomcat9 (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.5
libtomcat9-java (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.5
Tomcat - update to D.9.0.87.01
Netcool Operations Insight - update to 1.6.9
IBM Process Mining - update to 1.13.2
Storage Copy Data Management - update to 2.2.23.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.5
EMC ViPR SRM - update to 4.8.0.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.1
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.14.00.14
RecoverPoint for VMs - update to 6.0.SP1.P1
UrbanCode Build - update to 6.1.7.7
IBM Sterling Control Center - update to 6.2.1.0.14
UCD - IBM UrbanCode Deploy - addressed in versions 6.2.7.19, 7.0.5.14, 7.1.2.10, 7.2.3.3, 7.3.0.1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
tomcat-jsp-2_3-api - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-lib - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-javadoc - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1
tomcat-webapps - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-servlet-3_1-api - update to 8.0.53-29.57.1
tomcat-admin-webapps - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-el-3_0-api - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat-docs-webapp - addressed in versions 8.0.53-29.57.1, 9.0.36-3.93.1
tomcat-jsvc - update to 9.0.10-27
tomcat - update to 9.0.10-27
tomcat-help - update to 9.0.10-27
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1
tomcat9 (Debian package) - update to 9.0.43-2~deb11u6
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-13.redhat_00011.1.el7jws, 9.0.62-13.redhat_00011.1.el8jws, 9.0.62-13.redhat_00011.1.el9jws
tomcat9 - update to 9.0.71-1
www-servers/tomcat - update to 10.1.8
EMC NetWorker Server - update to 19.7.0.3
CloudBoost Virtual Appliance - update to 19.12.0.1
IBM Security SOAR - update to 47.1
External References
Related Security Bulletins
- HTTP request smuggling in Apache Tomcat
- SUSE update for tomcat
- SUSE update for tomcat
- SUSE update for tomcat
- SUSE update for tomcat
- Multiple vulnerabilities in IBM Data Risk Manager
- HTTP request smuggling in IBM UrbanCode Deploy
- HTTP request smuggling in IBM UrbanCode Build
- HTTP request smuggling in IBM Process Mining
- IBM Security SOAR update for Apache Tomcat
- Multiple vulnerabilities in Dell SRM and Dell Storage Monitoring and Reporting
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle Communications Instant Messaging Server
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in Oracle Financial Services Crime and Compliance Management Studio
- Multiple vulnerabilities in Oracle Agile PLM Framework
- Multiple vulnerabilities in IBM UrbanCode Release
- Inconsistent interpretation of HTTP requests in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Dell Secure Connect Gateway Policy Manager
- Inconsistent interpretation of HTTP requests in Dell NetWorker
- Multiple vulnerabilities in Axway SecureTransport (November 2022)
- Debian update for tomcat9
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Multiple vulnerabilities in Oracle Financial Services Model Management and Governance
- Multiple vulnerabilities in Management Cloud Engine
- Multiple vulnerabilities in Oracle Siebel CRM
- Gentoo update for Apache Tomcat
- Inconsistent interpretation of HTTP requests in IBM Cloud Pak for Data
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in Confluence Data Center and Server
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- openEuler update for tomcat
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Jira Software Data Center and Server update for tomcat-coyote
- Ubuntu update for tomcat8
- Amazon Linux AMI update for tomcat9
- HP-UX update for Tomcat
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Dell CloudBoost Virtual Appliance update for third-party components