cbcvebase.
CVE-2022-25762
published 2022-05-13

CVE-2022-25762: If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache…

PriorityP352high8.6CVSS 3.1
AVNACLPRNUINSUCHILAL
EPSS
8.03%
94.1th percentile
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

Affected

7 ranges
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat>= 8.5.0 < 8.5.768.5.76
apachetomcat>= 9.0.0 < 9.0.219.0.21
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
debiantomcat9< tomcat9 9.0.22-1 (bookworm)tomcat9 9.0.22-1 (bookworm)
oracleagile_plm

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv8.6HIGH
vendor_apache8.6HIGH
vendor_debian8.6HIGH
vendor_oracle8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.