peter bassill · operator
$ cve CVE-2022-29885 JSON

CVE-2022-29885 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 73.5% (pctl 99)

Patch early

A public exploit exists.

Description

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS73.47% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-400
On CISA KEVno
Public exploityes
Published2022-05-12
Last modified2026-06-17

Affected (3)

VendorProduct
apachetomcat
debiandebian linux
oraclehospitality cruise shipboard property management system

Public exploits

SourceTitleDate
exploit-dbApache Tomcat 10.1 - Denial Of Service2023-04-05

References

→ the Explorer  ·  watch your stack  ·  NVD