First published: Thu May 12 2022(Updated: )
Apache Tomcat is vulnerable to a denial of service, caused by an use-after-free flaw in theEncryptInterceptor in an untrusted network. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tomcat | >=8.5.38<=8.5.78 | |
Apache Tomcat | >=9.0.13<=9.0.62 | |
Apache Tomcat | >=10.0.0<=10.0.20 | |
Apache Tomcat | =10.1.0-milestone1 | |
Apache Tomcat | =10.1.0-milestone10 | |
Apache Tomcat | =10.1.0-milestone11 | |
Apache Tomcat | =10.1.0-milestone12 | |
Apache Tomcat | =10.1.0-milestone13 | |
Apache Tomcat | =10.1.0-milestone14 | |
Apache Tomcat | =10.1.0-milestone2 | |
Apache Tomcat | =10.1.0-milestone3 | |
Apache Tomcat | =10.1.0-milestone4 | |
Apache Tomcat | =10.1.0-milestone5 | |
Apache Tomcat | =10.1.0-milestone6 | |
Apache Tomcat | =10.1.0-milestone7 | |
Apache Tomcat | =10.1.0-milestone8 | |
Apache Tomcat | =10.1.0-milestone9 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Oracle Hospitality Cruise Shipboard Property Management System | =20.2.1 | |
maven/org.apache.tomcat:tomcat | >=8.5.38<8.5.79 | 8.5.79 |
maven/org.apache.tomcat:tomcat | >=9.0.13<9.0.63 | 9.0.63 |
maven/org.apache.tomcat:tomcat | >=10.0.0-M1<10.0.21 | 10.0.21 |
maven/org.apache.tomcat:tomcat | >=10.1.0-M1<10.1.0-M15 | 10.1.0-M15 |
debian/tomcat9 | 9.0.43-2~deb11u10 9.0.70-2 9.0.95-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29885 is a vulnerability in Apache Tomcat that incorrectly stated it enabled Tomcat clustering to run over an untrusted network.
CVE-2022-29885 affects Apache Tomcat versions 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62, and 8.5.38 to 8.5.78.
CVE-2022-29885 has a severity rating of 7.5 (high).
To fix CVE-2022-29885, you should update Apache Tomcat to version 9.0.31-1~deb10u10, 9.0.43-2~deb11u6, 9.0.43-2~deb11u9, or 9.0.70-2.
You can find more information about CVE-2022-29885 on the following references: [1](http://packetstormsecurity.com/files/171728/Apache-Tomcat-10.1-Denial-Of-Service.html), [2](https://lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcv), [3](https://lists.debian.org/debian-lts-announce/2022/10/msg00029.html).