CVE-2022-23181
Summary
| CVE | CVE-2022-23181 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-27 13:15:00 UTC |
| Updated | 2022-11-07 18:49:00 UTC |
| Description | The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| Debian -- Security Information -- DSA-5265-1 tomcat9 |
DEBIAN |
www.debian.org |
|
| CVE-2022-23181 Apache Tomcat Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| lists.apache.org/thread/l8x62p3k19yfcb208jo4zrb83k5mfwg9 |
MISC |
lists.apache.org |
|
| [SECURITY] [DLA 3160-1] tomcat9 security update |
MLIST |
lists.debian.org |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150472 Apache Tomcat Privilege Escalation Vulnerability (CVE-2022-23181)
- 181163 Debian Security Update for tomcat9 (DLA 3160-1)
- 181177 Debian Security Update for tomcat9 (DSA 5265-1)
- 184796 Debian Security Update for tomcat9 (CVE-2022-23181)
- 296062 Oracle Solaris 11.4 Support Repository Update (SRU) 43.113.3 Missing (CPUJAN2022)
- 353183 Amazon Linux Security Advisory for tomcat8 : ALAS-2022-1572
- 354480 Amazon Linux Security Advisory for tomcat : ALAS2022-2022-044
- 354519 Amazon Linux Security Advisory for tomcat9 : ALAS2022-2022-233
- 354529 Amazon Linux Security Advisory for tomcat9 : ALAS-2022-233
- 354572 Amazon Linux Security Advisory for tomcat9 : ALAS-2022-233
- 355337 Amazon Linux Security Advisory for tomcat9 : ALAS2023-2023-059
- 356202 Amazon Linux Security Advisory for tomcat : ALASTOMCAT9-2023-003
- 356224 Amazon Linux Security Advisory for tomcat : ALASTOMCAT8.5-2023-004
- 730348 Apache Tomcat Privilege Escalation Vulnerability
- 730510 Atlassian Jira Remote Code Execution (RCE) Vulnerability (JRASERVER-73223)
- 730575 Atlassian Jira Server and Data Center Multiple Servlet Apache Tomcat Vulnerability (JRASERVER-73739)
- 730646 Apache Tomcat Local Privilege Escalation Vulnerability (CVE-2020-9484)
- 730651 Apache Tomcat Local Privilege Escalation Vulnerability (CVE-2020-9484)
- 730660 Apache Tomcat Local Privilege Escalation Vulnerability (CVE-2020-9484)
- 730666 Apache Tomcat Local Privilege Escalation Vulnerability (CVE-2020-9484)
- 751788 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2022:0695-1)
- 751789 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2022:0694-1)
- 751846 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2022:0784-1)
- 751865 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2022:0818-1)
- 751877 OpenSUSE Security Update for tomcat (openSUSE-SU-2022:0818-1)