Code Injection in Apache Tomcat - CVE-2022-45143
Published: January 3, 2023
Vulnerability details
The vulnerability allows a remote attacker to manipulate server output.
The vulnerability exists due to improper input validation within the JsonErrorReportValve when handling type, message or description values. A remote attacker can send a specially crafted request and manipulate or invalidate JSON output.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
JBoss Web Server
Confluence Server
Debian Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Oracle Solaris
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Web and Scripting Module
openSUSE Leap
Red Hat Openshift Application Runtimes
IBM App Connect Professional
IBM Process Mining
IBM UrbanCode Release
IBM Rational Build Forge
Oracle Communications Diameter Signaling Router
Oracle Communications Session Report Manager
Oracle SD-WAN Edge
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Confluence Data Center
IBM Maximo Application Suite
SecureTransport
Oracle Agile Engineering Data Management
Cloud Pak for Network Automation
Dell Policy Manager for Secure Connect Gateway (SCG)
UrbanCode Build
MySQL Enterprise Monitor
Oracle Financial Services Compliance Studio
Oracle Communications Element Manager
IBM Data Risk Manager
Oracle Agile PLM Framework
Oracle Commerce Guided Search
Tomcat
tomcat9 (Debian package)
tomcat-el-3_0-api
tomcat-admin-webapps
tomcat-embed
tomcat-docs-webapp
tomcat-jsp-2_3-api
tomcat-javadoc
tomcat-webapps
tomcat-lib
tomcat
tomcat-jsvc
tomcat-servlet-4_0-api
jws5-tomcat (Red Hat package)
tomcat9
www-servers/tomcat
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
Fuse
How to mitigate CVE-2022-45143
IBM Process Mining - update to 1.14.0.0
SecureTransport - update to 5.5-20230126
JBoss Web Server - update to 5.7.2
IBM UrbanCode Release - update to 6.2.5.8
IBM Rational Build Forge - update to 8.0.0.24
Tomcat - update to D.9.0.87.01
Netcool Operations Insight - update to 1.6.9
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM Data Risk Manager - update to 2.0.6.16
Cloud Pak for Network Automation - update to 2.4.4
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.5
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.14.00.14
UrbanCode Build - update to 6.1.7.7
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
IBM App Connect Professional - update to 7.5.5.0
Fuse - update to 7.12.0
Confluence Data Center - addressed in versions 7.13.15, 7.19.16, 8.1.1, 8.2.0
Confluence Server - addressed in versions 7.13.15, 7.19.16, 8.1.1, 8.2.0
IBM Maximo Application Suite - addressed in versions 8.9.6, 8.10.4
tomcat9 (Debian package) - update to 9.0.43-2~deb11u6
tomcat-el-3_0-api - update to 9.0.43-150200.38.1
tomcat-admin-webapps - update to 9.0.43-150200.38.1
tomcat-embed - update to 9.0.43-150200.38.1
tomcat-docs-webapp - update to 9.0.43-150200.38.1
tomcat-jsp-2_3-api - update to 9.0.43-150200.38.1
tomcat-javadoc - update to 9.0.43-150200.38.1
tomcat-webapps - update to 9.0.43-150200.38.1
tomcat-lib - update to 9.0.43-150200.38.1
tomcat - update to 9.0.43-150200.38.1
tomcat-jsvc - update to 9.0.43-150200.38.1
tomcat-servlet-4_0-api - update to 9.0.43-150200.38.1
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-13.redhat_00011.1.el7jws, 9.0.62-13.redhat_00011.1.el8jws, 9.0.62-13.redhat_00011.1.el9jws
tomcat9 - update to 9.0.71-1
www-servers/tomcat - update to 10.1.8
External References
Related Security Bulletins
- Code injection in Apache Tomcat
- Code injection in IBM UrbanCode Release
- Code Injection in IBM UrbanCode Build
- Code Injection in IBM App Connect Professional
- Multiple vulnerabilities in Dell Secure Connect Gateway Policy Manager
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in Oracle Solaris
- Multiple vulnerabilities in Axway SecureTransport (January 2023)
- Debian update for tomcat9
- Multiple vulnerabilities in Red Hat JBoss Web Server
- SUSE update for tomcat
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle SD-WAN Edge
- Multiple vulnerabilities in Oracle Communications Session Report Manager
- Multiple vulnerabilities in Oracle Communications Element Manager
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Oracle Commerce Guided Search
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in Oracle Agile PLM Framework
- Code injection in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Code injection in IBM Process Mining
- Gentoo update for Apache Tomcat
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Oracle Commerce Guided Search
- Multiple vulnerabilities in Oracle Agile Engineering Data Management
- Multiple vulnerabilities in IBM Maximo Application Suite - Monitor Component
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Red Hat Openshift Application Runtimes
- Multiple vulnerabilities in IBM Data Risk Manager
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Rational Build Forge
- Confluence Data Center and Server update for Apache Tomcat
- Amazon Linux AMI update for tomcat9
- HP-UX update for Tomcat
- Multiple vulnerabilities in Fuse 7
- Code Injection in Oracle Financial Services Compliance Studio