Code Injection in Apache Tomcat - CVE-2022-45143

 

Code Injection in Apache Tomcat - CVE-2022-45143

Published: January 3, 2023


Vulnerability identifier: #VU70666
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45143
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to manipulate server output.

The vulnerability exists due to improper input validation within the JsonErrorReportValve when handling type, message or description values. A remote attacker can send a specially crafted request and manipulate or invalidate JSON output.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Apache Tomcat
JBoss Web Server
Confluence Server
Debian Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Oracle Solaris
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Web and Scripting Module
openSUSE Leap
Red Hat Openshift Application Runtimes
IBM App Connect Professional
IBM Process Mining
IBM UrbanCode Release
IBM Rational Build Forge
Oracle Communications Diameter Signaling Router
Oracle Communications Session Report Manager
Oracle SD-WAN Edge
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Confluence Data Center
IBM Maximo Application Suite
SecureTransport
Oracle Agile Engineering Data Management
Cloud Pak for Network Automation
Dell Policy Manager for Secure Connect Gateway (SCG)
UrbanCode Build
MySQL Enterprise Monitor
Oracle Financial Services Compliance Studio
Oracle Communications Element Manager
IBM Data Risk Manager
Oracle Agile PLM Framework
Oracle Commerce Guided Search
Tomcat
tomcat9 (Debian package)
tomcat-el-3_0-api
tomcat-admin-webapps
tomcat-embed
tomcat-docs-webapp
tomcat-jsp-2_3-api
tomcat-javadoc
tomcat-webapps
tomcat-lib
tomcat
tomcat-jsvc
tomcat-servlet-4_0-api
jws5-tomcat (Red Hat package)
tomcat9
www-servers/tomcat
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
Fuse

How to mitigate CVE-2022-45143

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.84, 9.0.69, 10.1.2
IBM Process Mining - update to 1.14.0.0
SecureTransport - update to 5.5-20230126
JBoss Web Server - update to 5.7.2
IBM UrbanCode Release - update to 6.2.5.8
IBM Rational Build Forge - update to 8.0.0.24
Tomcat - update to D.9.0.87.01
Netcool Operations Insight - update to 1.6.9
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM Data Risk Manager - update to 2.0.6.16
Cloud Pak for Network Automation - update to 2.4.4
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.5
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.14.00.14
UrbanCode Build - update to 6.1.7.7
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
IBM App Connect Professional - update to 7.5.5.0
Fuse - update to 7.12.0
Confluence Data Center - addressed in versions 7.13.15, 7.19.16, 8.1.1, 8.2.0
Confluence Server - addressed in versions 7.13.15, 7.19.16, 8.1.1, 8.2.0
IBM Maximo Application Suite - addressed in versions 8.9.6, 8.10.4
tomcat9 (Debian package) - update to 9.0.43-2~deb11u6
tomcat-el-3_0-api - update to 9.0.43-150200.38.1
tomcat-admin-webapps - update to 9.0.43-150200.38.1
tomcat-embed - update to 9.0.43-150200.38.1
tomcat-docs-webapp - update to 9.0.43-150200.38.1
tomcat-jsp-2_3-api - update to 9.0.43-150200.38.1
tomcat-javadoc - update to 9.0.43-150200.38.1
tomcat-webapps - update to 9.0.43-150200.38.1
tomcat-lib - update to 9.0.43-150200.38.1
tomcat - update to 9.0.43-150200.38.1
tomcat-jsvc - update to 9.0.43-150200.38.1
tomcat-servlet-4_0-api - update to 9.0.43-150200.38.1
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-13.redhat_00011.1.el7jws, 9.0.62-13.redhat_00011.1.el8jws, 9.0.62-13.redhat_00011.1.el9jws
tomcat9 - update to 9.0.71-1
www-servers/tomcat - update to 10.1.8

External References

Related Security Bulletins