CVE-2022-29885
Vulnerability Summary
Timeline
Description
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 55.53%• Percentile: 98%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Affected Systems
- apache software foundation•apache tomcat
Apache Tomcat 10.1 10.1.0-M1 to 10.1.0-M14 | Apache Tomcat 10 10.0.0-M1 to 10.0.20 | Apache Tomcat 9 9.0.13 to 9.0.62 | Apache Tomcat 8.5 8.5.38 to 8.5.78
- Unknown•Tomcat
≥ 8.5.38, ≤ 8.5.78 | ≥ 9.0.13, ≤ 9.0.62 | ≥ 10.0.0, ≤ 10.0.20 | 10.1.0:milestone1 | 10.1.0:milestone10 | 10.1.0:milestone11 | 10.1.0:milestone12 | 10.1.0:milestone13 | 10.1.0:milestone14 | 10.1.0:milestone2 | 10.1.0:milestone3 | 10.1.0:milestone4 | 10.1.0:milestone5 | 10.1.0:milestone6 | 10.1.0:milestone7 | 10.1.0:milestone8 | 10.1.0:milestone9
- debian•debian_linux
10.0 | 11.0
- org.apache.tomcat•tomcat
≥ 10.1.0-M1, < 10.1.0-M15 | ≥ 10.0.0-M1, < 10.0.21 | ≥ 9.0.13, < 9.0.63 | ≥ 8.5.38, < 8.5.79
- oracle•hospitality_cruise_shipboard_property_management_system
20.2.1
References (13)
- https://lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcv
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://security.netapp.com/advisory/ntap-20220629-0002/
- https://lists.debian.org/debian-lts-announce/2022/10/msg00029.html
- https://www.debian.org/security/2022/dsa-5265
- http://packetstormsecurity.com/files/171728/Apache-Tomcat-10.1-Denial-Of-Service.html
- https://nvd.nist.gov/vuln/detail/CVE-2022-29885
- https://github.com/apache/tomcat/commit/0fa7721f11d565a2cd2e44366c388ad6a3e6357d
- https://github.com/apache/tomcat/commit/36826ea638457d7e17876a70f89cb435b6db0d91
- https://github.com/apache/tomcat/commit/b679bc627f5a4ea6510af95adfb7476b07eba890
- https://github.com/apache/tomcat/commit/eaafd28296c54d983e28a47953c1f5cb2c334f48
- https://github.com/apache/tomcat
- https://security.netapp.com/advisory/ntap-20220629-0002