CVE-2022-29885
published 2022-05-12CVE-2022-29885: The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly…
PriorityP272high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EXPLOIT
EPSS
73.14%
99.4th percentile
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | 10.0.0 – 10.0.20 | — |
| apache | tomcat | 8.5.38 – 8.5.78 | — |
| apache | tomcat | 9.0.13 – 9.0.62 | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.63-1 (bookworm) | tomcat9 9.0.63-1 (bookworm) |
| oracle | hospitality_cruise_shipboard_property_management_system | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
FLT2002
- →Detect large repeated TCP payloads beginning with the magic bytes 'FLT2002' sent to the Tomcat clustering port (default 4000); multiple concurrent connections sending this pattern indicate a DoS attempt exploiting CVE-2022-29885. ↗
- →The exploit spawns 5 concurrent threads each sending the malformed cluster message in a tight loop; high-volume concurrent connections to the clustering port from a single source should be alerted on. ↗
- →CVE-2022-29885 is exploitable even when EncryptInterceptor is enabled; presence of EncryptInterceptor in Tomcat cluster config does NOT rule out DoS exposure over untrusted networks. ↗
- ·EncryptInterceptor provides confidentiality and integrity but does NOT protect against DoS risks on untrusted networks, contrary to prior documentation claims. ↗
- ·Tomcat clustering exposed on any untrusted or public network segment remains vulnerable to DoS regardless of EncryptInterceptor configuration; a VPN or equivalent network isolation is required for full protection. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2024-08-01·CVSS 7.0
CVE-2020-9484 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly handled certain uncommon
PersistenceManager with FileStore configurations. A remote attacker could
possibly use this issue to execute arbitrary code. This issue only affected
tomcat8 for Ubuntu 18.04 LTS (CVE-2020-9484)
It was discovered that Tomcat incorrectly handled certain HTTP/2 connection
requests. A remote attacker could use this issue to obtain wrong responses
possibly containing sensitive information. This issue only affected tomcat8
for Ubuntu 18.04 LTS (CVE-2021-25122)
Thomas Wozenilek discovered that Tomcat incorrectly handled certain TLS
packets. A remote attacker could possibly use this issue to cause a denial
of service. This issue only affected
Oracle
Oracle Oracle Communications Risk Matrix: BEServer (Apache Tomcat) — CVE-2022-29885
vendor_oracle·2022-10-15·CVSS 7.5
CVE-2022-29885 [HIGH] Oracle Oracle Communications Risk Matrix: BEServer (Apache Tomcat) — CVE-2022-29885
Oracle Oracle Communications Risk Matrix: BEServer (Apache Tomcat) vulnerability
CVE: CVE-2022-29885
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Hospitality Applications Risk Matrix: Next-Gen SPMS (Apache Tomcat) — CVE-2022-29885
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2022-29885 [HIGH] Oracle Oracle Hospitality Applications Risk Matrix: Next-Gen SPMS (Apache Tomcat) — CVE-2022-29885
Oracle Oracle Hospitality Applications Risk Matrix: Next-Gen SPMS (Apache Tomcat) vulnerability
CVE: CVE-2022-29885
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Red Hat
tomcat: EncryptInterceptor documentation mistake
vendor_redhat·2022-05-10·CVSS 7.5
CVE-2022-29885 [HIGH] CWE-1112 tomcat: EncryptInterceptor documentation mistake
tomcat: EncryptInterceptor documentation mistake
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
Statement: This flaw describes a mistake made in the documentation which overstated the protection provided by the clustering feature. As the impact is Low and a patch would not directly improve the security posture of Apache Tomcat, this flaw is marked as will not fix for all Red Hat products. This
Debian
CVE-2022-29885: tomcat9 - The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20...
vendor_debian·2022·CVSS 7.5
CVE-2022-29885 [HIGH] CVE-2022-29885: tomcat9 - The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20...
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
Scope: local
bookworm: resolved (fixed in 9.0.63-1)
bullseye: resolved (fixed in 9.0.43-2~deb11u4)
forky: resolved (fixed in 9.0.63-1)
sid: resolved (fixed in 9.0.63-1)
trixie: resolved (fixed in 9.0.63-1)
Apache
Apache tomcat: CVE-2022-29885
vendor_apache·CVSS 7.5
CVE-2022-29885 [HIGH] Apache tomcat: CVE-2022-29885
Apache tomcat: CVE-2022-29885
The documentation for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks. This was fixed with commit b679bc62 . This issue was reported to the Apache Tomcat Security team by 4ra1n on 17 April 2022. The issue was made public on 10 May 2022. Affects: 8.5.38 to 8.5.78 1 April 2022 Fixed in Apache Tomcat 8.5.78 High: Information Disclosure
OSV
tomcat8, tomcat9 vulnerabilities
osv·2024-08-01·CVSS 7.0
CVE-2020-9484 [HIGH] tomcat8, tomcat9 vulnerabilities
tomcat8, tomcat9 vulnerabilities
It was discovered that Tomcat incorrectly handled certain uncommon
PersistenceManager with FileStore configurations. A remote attacker could
possibly use this issue to execute arbitrary code. This issue only affected
tomcat8 for Ubuntu 18.04 LTS (CVE-2020-9484)
It was discovered that Tomcat incorrectly handled certain HTTP/2 connection
requests. A remote attacker could use this issue to obtain wrong responses
possibly containing sensitive information. This issue only affected tomcat8
for Ubuntu 18.04 LTS (CVE-2021-25122)
Thomas Wozenilek discovered that Tomcat incorrectly handled certain TLS
packets. A remote attacker could possibly use this issue to cause a denial
of service. This issue only affected tomcat8 for Ubuntu 18.04 LTS
(CVE-2021-41079)
Trung
OSV
Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption
osv·2022-05-13
CVE-2022-29885 [HIGH] Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption
Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
GHSA
Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption
ghsa·2022-05-13
CVE-2022-29885 [HIGH] CWE-400 Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption
Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
OSV
CVE-2022-29885: The documentation of Apache Tomcat 10
osv·2022-05-12·CVSS 7.5
CVE-2022-29885 [HIGH] CVE-2022-29885: The documentation of Apache Tomcat 10
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/171728/Apache-Tomcat-10.1-Denial-Of-Service.htmlhttps://lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcvhttps://lists.debian.org/debian-lts-announce/2022/10/msg00029.htmlhttps://security.netapp.com/advisory/ntap-20220629-0002/https://www.debian.org/security/2022/dsa-5265https://www.oracle.com/security-alerts/cpujul2022.htmlhttp://packetstormsecurity.com/files/171728/Apache-Tomcat-10.1-Denial-Of-Service.htmlhttps://lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcvhttps://lists.debian.org/debian-lts-announce/2022/10/msg00029.htmlhttps://security.netapp.com/advisory/ntap-20220629-0002/https://www.debian.org/security/2022/dsa-5265https://www.oracle.com/security-alerts/cpujul2022.html
2022-05-12
Published