CVE-2022-29885

Aliases:GHSA-r84p-88g2-2vx2BIT-tomcat-2022-29885
Modified
Published: 12 May 2022, 00:00
Last modified:03 Aug 2024, 06:33

Vulnerability Summary

Overall Risk (default)
high
51/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
55.53% CRITICAL
56% probability -4.58%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

12 May 2022, 00:00
Published
Vulnerability first disclosed
03 Aug 2024, 06:33
Last Modified
Vulnerability information updated

Description

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 55.53% Percentile: 98%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • apache software foundationapache tomcat

    Apache Tomcat 10.1 10.1.0-M1 to 10.1.0-M14 | Apache Tomcat 10 10.0.0-M1 to 10.0.20 | Apache Tomcat 9 9.0.13 to 9.0.62 | Apache Tomcat 8.5 8.5.38 to 8.5.78

  • UnknownTomcat

    ≥ 8.5.38, ≤ 8.5.78 | ≥ 9.0.13, ≤ 9.0.62 | ≥ 10.0.0, ≤ 10.0.20 | 10.1.0:milestone1 | 10.1.0:milestone10 | 10.1.0:milestone11 | 10.1.0:milestone12 | 10.1.0:milestone13 | 10.1.0:milestone14 | 10.1.0:milestone2 | 10.1.0:milestone3 | 10.1.0:milestone4 | 10.1.0:milestone5 | 10.1.0:milestone6 | 10.1.0:milestone7 | 10.1.0:milestone8 | 10.1.0:milestone9

  • debiandebian_linux

    10.0 | 11.0

  • org.apache.tomcattomcat

    ≥ 10.1.0-M1, < 10.1.0-M15 | ≥ 10.0.0-M1, < 10.0.21 | ≥ 9.0.13, < 9.0.63 | ≥ 8.5.38, < 8.5.79

  • oraclehospitality_cruise_shipboard_property_management_system

    20.2.1

References (13)