CVE-2022-34305
published 2022-06-23CVE-2022-34305: In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web…
PriorityP182medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
6.16%
92.7th percentile
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | 10.0.0 – 10.0.22 | — |
| apache | tomcat | 8.5.50 – 8.5.81 | — |
| apache | tomcat | 9.0.30 – 9.0.64 | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| debian | tomcat9 | < tomcat9 9.0.65-1 (bookworm) | tomcat9 9.0.65-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
url/examples/jsp/security/protected/index.jsp?dataName=%3Cscript%3Ealert(document.domain)%3C/script%3E&dataValue=demo↗
- →Detect XSS exploitation attempt via the dataName parameter in the Tomcat examples web application; look for unencoded or encoded script tags in the dataName query parameter of index.jsp requests. ↗
- →Match HTTP responses containing both 'alert(document.domain)' in the body with status 200 and content-type text/html to confirm successful XSS reflection in the Tomcat examples app. ↗
- →Detect default credential login attempts against the Tomcat examples protected JSP endpoint; monitor POST to j_security_check with credentials tomcat:tomcat followed by a response body containing 'You are logged in as remote user'. ↗
- →Extract and track jsessionid values from the Form authentication example page action attribute to identify session tokens used in exploitation chains. ↗
- →Use Shodan/FOFA queries to identify exposed Apache Tomcat instances; presence of the /examples/ web application on internet-facing servers indicates attack surface for CVE-2022-34305. ↗
- ·The XSS vulnerability is specifically in the Form authentication example within the examples web application; the vulnerability only exists if the examples web application is deployed and accessible — it is not present in the core Tomcat runtime. ↗
- ·The exploit flow requires two sequential HTTP steps: first a GET to retrieve the jsessionid from the form action, then a POST to authenticate, before the XSS payload can be triggered — single-request detections will miss the full attack chain. ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vulncheck6.1MEDIUM
vendor_apache6.1LOW
vendor_debian6.1LOW
vendor_oracle6.1MEDIUM
vendor_redhat6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: MFT Runtime Server (Apache Tomcat) — CVE-2022-34305
vendor_oracle·2023-04-15·CVSS 6.1
CVE-2022-34305 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: MFT Runtime Server (Apache Tomcat) — CVE-2022-34305
Oracle Oracle Fusion Middleware Risk Matrix: MFT Runtime Server (Apache Tomcat) vulnerability
CVE: CVE-2022-34305
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Backend Server (Apache Tomcat) — CVE-2022-34305
vendor_oracle·2023-01-15·CVSS 6.1
CVE-2022-34305 [MEDIUM] Oracle Oracle Communications Risk Matrix: Backend Server (Apache Tomcat) — CVE-2022-34305
Oracle Oracle Communications Risk Matrix: Backend Server (Apache Tomcat) vulnerability
CVE: CVE-2022-34305
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: REST API (Apache Tomcat) — CVE-2022-34305
vendor_oracle·2022-10-15·CVSS 6.1
CVE-2022-34305 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: REST API (Apache Tomcat) — CVE-2022-34305
Oracle Oracle Communications Applications Risk Matrix: REST API (Apache Tomcat) vulnerability
CVE: CVE-2022-34305
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Red Hat
tomcat: XSS in examples web application
vendor_redhat·2022-06-23·CVSS 6.1
CVE-2022-34305 [MEDIUM] CWE-79 tomcat: XSS in examples web application
tomcat: XSS in examples web application
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
A flaw was found in the Apache Tomcat package. An example web application did not filter the form authentication example, exposing a Cross-site scripting (XSS) vulnerability.
Statement: Red Hat Satellite does not include the affected Apache Tomcat, however, Tomcat is shipped with Red Hat Enterprise Linux and consumed by the Candlepin component of Satellite. Red Hat Satellite users are therefore advised to check the impact state of Red Hat Enterprise Linux, since any necessary fixes will be distributed throug
Debian
CVE-2022-34305: tomcat9 - In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64...
vendor_debian·2022·CVSS 6.1
CVE-2022-34305 [MEDIUM] CVE-2022-34305: tomcat9 - In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64...
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
Scope: local
bookworm: resolved (fixed in 9.0.65-1)
bullseye: resolved (fixed in 9.0.65-1)
forky: resolved (fixed in 9.0.65-1)
sid: resolved (fixed in 9.0.65-1)
trixie: resolved (fixed in 9.0.65-1)
Apache
Apache tomcat: CVE-2022-34305
vendor_apache·CVSS 6.1
CVE-2022-34305 [LOW] Apache tomcat: CVE-2022-34305
Apache tomcat: CVE-2022-34305
The Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability. This was fixed with commit 5f6c88b0 . This issue was reported to the Apache Tomcat Security team on 22 June 2022. The issue was made public on 23 June 2022. Affects: 8.5.50 to 8.5.81 2022-05-23 Fixed in Apache Tomcat 8.5.79 Low: Apache Tomcat EncryptInterceptor DoS
Severity: low
OSV
Cross-site Scripting in Apache Tomcat
osv·2022-06-24
CVE-2022-34305 [MEDIUM] Cross-site Scripting in Apache Tomcat
Cross-site Scripting in Apache Tomcat
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
GHSA
Cross-site Scripting in Apache Tomcat
ghsa·2022-06-24
CVE-2022-34305 [MEDIUM] CWE-79 Cross-site Scripting in Apache Tomcat
Cross-site Scripting in Apache Tomcat
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
OSV
CVE-2022-34305: In Apache Tomcat 10
osv·2022-06-23·CVSS 6.1
CVE-2022-34305 [MEDIUM] CVE-2022-34305: In Apache Tomcat 10
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
VulnCheck
Apache Tomcat Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
vulncheck·2022·CVSS 6.1
CVE-2022-34305 [MEDIUM] Apache Tomcat Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Apache Tomcat Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
Affected: Apache Tomcat
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2023/11/09055246/Modern-Asian-APT-groups-TTPs_report_eng.pdf
No detection rules found.
Nuclei
Apache Tomcat - Default Login Discovery
nuclei·CVSS 6.1
[MEDIUM] Apache Tomcat - Default Login Discovery
Apache Tomcat - Default Login Discovery
Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 default login credentials were successful.
Template:
id: tomcat-examples-login
info:
name: Apache Tomcat - Default Login Discovery
author: 0xelkomy & C0NQR0R
severity: info
description: Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 default login credentials were successful.
reference:
- https://c0nqr0r.github.io/CVE-2022-34305/
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cvss-score: 0
cwe-id: CWE-200
metadata:
verified: true
max-request: 2
tags: default-login,tomcat,vuln
http:
- raw:
- |
GET /examples/jsp/security/protected/index.jsp HTTP/1.1
Host: {{Hostname}}
- |
Nuclei
Apache Tomcat Examples Web Application - Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2022-34305 [MEDIUM] Apache Tomcat Examples Web Application - Cross-Site Scripting
Apache Tomcat Examples Web Application - Cross-Site Scripting
Apache Tomcat 8.5.50 to 8.5.81, 9.0.30 to 9.0.64, 10.0.0-M1 to 10.0.22, and 10.1.0-M1 to 10.1.0-M16 contain a reflected cross-site scripting caused by displaying unfiltered user data in the Form authentication example, letting attackers execute scripts in victim browsers, exploit requires attacker to craft malicious input.
Template:
id: CVE-2022-34305
info:
name: Apache Tomcat Examples Web Application - Cross-Site Scripting
author: Sourabh-Sahu
severity: medium
description: |
Apache Tomcat 8.5.50 to 8.5.81, 9.0.30 to 9.0.64, 10.0.0-M1 to 10.0.22, and 10.1.0-M1 to 10.1.0-M16 contain a reflected cross-site scripting caused by displaying unfiltered user data in the Form authentication example, letting attackers execute scripts
Bugzilla
CVE-2022-34305 tomcat: XSS in examples web application
bugzilla·2022-06-30·CVSS 6.1
CVE-2022-34305 [MEDIUM] CVE-2022-34305 tomcat: XSS in examples web application
CVE-2022-34305 tomcat: XSS in examples web application
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
https://lists.apache.org/thread/k04zk0nq6w57m72w5gb0r6z9ryhmvr4k
http://www.openwall.com/lists/oss-security/2022/06/23/1
Discussion:
Created tomcat tracking bugs for this issue:
Affects: fedora-all [bug 2102819]
Tenable
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
blogs_tenable·2022-10-19
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://www.openwall.com/lists/oss-security/2022/06/23/1https://lists.apache.org/thread/k04zk0nq6w57m72w5gb0r6z9ryhmvr4khttps://security.gentoo.org/glsa/202208-34https://security.netapp.com/advisory/ntap-20220729-0006/http://www.openwall.com/lists/oss-security/2022/06/23/1https://lists.apache.org/thread/k04zk0nq6w57m72w5gb0r6z9ryhmvr4khttps://security.gentoo.org/glsa/202208-34https://security.netapp.com/advisory/ntap-20220729-0006/
2022-06-23
Published
Exploited in the wild