#VU60079 Security restrictions bypass in Apache Tomcat - CVE-2022-23181
Published: January 27, 2022 / Updated: January 28, 2022
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a time of check, time of use flaw when configured to persist sessions using the FileStore. A local user can perform certain actions which lead to security restrictions bypass and privilege escalation (code execution with Tomcat process privileges).