CVE-2022-23181
published 2022-01-27CVE-2022-23181: The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to…
PriorityP432high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.69%
48.8th percentile
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | 10.0.1 – 10.0.14 | — |
| apache | tomcat | 8.5.55 – 8.5.73 | — |
| apache | tomcat | 9.0.35 – 9.0.56 | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.58-1 (bookworm) | tomcat9 9.0.58-1 (bookworm) |
| oracle | agile_engineering_data_management | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| oracle | managed_file_transfer | — | — |
| oracle | managed_file_transfer | — | — |
| oracle | mysql_enterprise_monitor | <= 8.0.29 | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
ghsa7.0HIGH
osv7.0HIGH
vendor_debian7.0HIGH
vendor_oracle7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2024-08-01·CVSS 7.0
CVE-2020-9484 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly handled certain uncommon
PersistenceManager with FileStore configurations. A remote attacker could
possibly use this issue to execute arbitrary code. This issue only affected
tomcat8 for Ubuntu 18.04 LTS (CVE-2020-9484)
It was discovered that Tomcat incorrectly handled certain HTTP/2 connection
requests. A remote attacker could use this issue to obtain wrong responses
possibly containing sensitive information. This issue only affected tomcat8
for Ubuntu 18.04 LTS (CVE-2021-25122)
Thomas Wozenilek discovered that Tomcat incorrectly handled certain TLS
packets. A remote attacker could possibly use this issue to cause a denial
of service. This issue only affected
Oracle
Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Apache Tomcat) — CVE-2022-23181
vendor_oracle·2023-04-15·CVSS 7.0
CVE-2022-23181 [HIGH] Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Apache Tomcat) — CVE-2022-23181
Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Apache Tomcat) vulnerability
CVE: CVE-2022-23181
CVSS: 7.0
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Installation (Apache Tomcat) — CVE-2022-23181
vendor_oracle·2022-10-15·CVSS 7.0
CVE-2022-23181 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Installation (Apache Tomcat) — CVE-2022-23181
Oracle Oracle Communications Applications Risk Matrix: Installation (Apache Tomcat) vulnerability
CVE: CVE-2022-23181
CVSS: 7.0
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Apache Tomcat) — CVE-2022-23181
vendor_oracle·2022-07-15·CVSS 7.0
CVE-2022-23181 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Studio (Apache Tomcat) — CVE-2022-23181
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Apache Tomcat) vulnerability
CVE: CVE-2022-23181
CVSS: 7.0
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Policy (Apache Tomcat) — CVE-2022-23181
vendor_oracle·2022-04-15·CVSS 7.0
CVE-2022-23181 [HIGH] Oracle Oracle Communications Risk Matrix: Policy (Apache Tomcat) — CVE-2022-23181
Oracle Oracle Communications Risk Matrix: Policy (Apache Tomcat) vulnerability
CVE: CVE-2022-23181
CVSS: 7.0
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2022 (APR 2022)
Red Hat
tomcat: local privilege escalation vulnerability
vendor_redhat·2022-01-26·CVSS 7.0
CVE-2022-23181 [HIGH] CWE-367 tomcat: local privilege escalation vulnerability
tomcat: local privilege escalation vulnerability
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
Statement: In Red Hat Enterprise Linux 8, Red Hat Certificate System 10 and Identity Management are using the `pki-servlet-engine` component. This component embeds a version of Tomcat which is not affected by this flaw, as it does not include the fix for CVE-2020-9484. Additionally, in these specific contexts, the prerequisites to the vulnerabilit
Debian
CVE-2022-23181: tomcat9 - The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerabil...
vendor_debian·2022·CVSS 7.0
CVE-2022-23181 [HIGH] CVE-2022-23181: tomcat9 - The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerabil...
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
Scope: local
bookworm: resolved (fixed in 9.0.58-1)
bullseye: resolved (fixed in 9.0.43-2~deb11u4)
forky: resolved (fixed in 9.0.58-1)
sid: resolved (fixed in 9.0.58-1)
trixie: resolved (fixed in 9.0.58-1)
OSV
tomcat8, tomcat9 vulnerabilities
osv·2024-08-01·CVSS 7.0
CVE-2020-9484 [HIGH] tomcat8, tomcat9 vulnerabilities
tomcat8, tomcat9 vulnerabilities
It was discovered that Tomcat incorrectly handled certain uncommon
PersistenceManager with FileStore configurations. A remote attacker could
possibly use this issue to execute arbitrary code. This issue only affected
tomcat8 for Ubuntu 18.04 LTS (CVE-2020-9484)
It was discovered that Tomcat incorrectly handled certain HTTP/2 connection
requests. A remote attacker could use this issue to obtain wrong responses
possibly containing sensitive information. This issue only affected tomcat8
for Ubuntu 18.04 LTS (CVE-2021-25122)
Thomas Wozenilek discovered that Tomcat incorrectly handled certain TLS
packets. A remote attacker could possibly use this issue to cause a denial
of service. This issue only affected tomcat8 for Ubuntu 18.04 LTS
(CVE-2021-41079)
Trung
OSV
Race condition in Apache Tomcat
osv·2022-02-01·CVSS 7.0
CVE-2022-23181 [HIGH] Race condition in Apache Tomcat
Race condition in Apache Tomcat
The fix for bug CVE-2020-9484 introduced a time of check time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
GHSA
Race condition in Apache Tomcat
ghsa·2022-02-01·CVSS 7.0
CVE-2022-23181 [HIGH] CWE-367 Race condition in Apache Tomcat
Race condition in Apache Tomcat
The fix for bug CVE-2020-9484 introduced a time of check time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
OSV
CVE-2022-23181: The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10
osv·2022-01-27·CVSS 7.0
CVE-2022-23181 [HIGH] CVE-2022-23181: The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread/l8x62p3k19yfcb208jo4zrb83k5mfwg9https://lists.debian.org/debian-lts-announce/2022/10/msg00029.htmlhttps://security.netapp.com/advisory/ntap-20220217-0010/https://www.debian.org/security/2022/dsa-5265https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://lists.apache.org/thread/l8x62p3k19yfcb208jo4zrb83k5mfwg9https://lists.debian.org/debian-lts-announce/2022/10/msg00029.htmlhttps://security.netapp.com/advisory/ntap-20220217-0010/https://www.debian.org/security/2022/dsa-5265https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2022-01-27
Published