QID 150531
Date Published: 2022-06-27
QID 150531: Apache Tomcat EncryptInterceptor DoS Vulnerability (CVE-2022-29885)
Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.
In affected versions of Apache Tomcat, the documentation for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
Affected Versions:
Apache Tomcat 10.1.0-M1 to 10.1.0-M14
Apache Tomcat 10.0.0-M1 to 10.0.20
Apache Tomcat 9.0.13 to 9.0.62
Apache Tomcat 8.5.38 to 8.5.78
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to a invalid URL and based on the response confirms the vulnerable instance of Apache Tomcat running on the host.
Successful exploitation of the vulnerability can allow an attacker to trigger a DoS via an Uncontrolled Resource Consumption
- Apache Tomcat -
lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcv
CVEs related to QID 150531
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Tomcat |
|