CVE-2022-29885 EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 73.5% (pctl 99)
Patch early
A public exploit exists.
Description
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 73.47% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-400 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2022-05-12 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| apache | tomcat |
| debian | debian linux |
| oracle | hospitality cruise shipboard property management system |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache Tomcat 10.1 - Denial Of Service | 2023-04-05 |
References
- http://packetstormsecurity.com/files/171728/Apache-Tomcat-10.1-Denial-Of-Service.html
- https://lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcv
- https://lists.debian.org/debian-lts-announce/2022/10/msg00029.html
- https://security.netapp.com/advisory/ntap-20220629-0002/
- https://www.debian.org/security/2022/dsa-5265
- https://www.oracle.com/security-alerts/cpujul2022.html
- http://packetstormsecurity.com/files/171728/Apache-Tomcat-10.1-Denial-Of-Service.html
- https://lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcv
- https://lists.debian.org/debian-lts-announce/2022/10/msg00029.html
- https://security.netapp.com/advisory/ntap-20220629-0002/
- https://www.debian.org/security/2022/dsa-5265
- https://www.oracle.com/security-alerts/cpujul2022.html
→ the Explorer · watch your stack · NVD