QID 150531

Date Published: 2022-06-27

QID 150531: Apache Tomcat EncryptInterceptor DoS Vulnerability (CVE-2022-29885)

Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.

In affected versions of Apache Tomcat, the documentation for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

Affected Versions:
Apache Tomcat 10.1.0-M1 to 10.1.0-M14
Apache Tomcat 10.0.0-M1 to 10.0.20
Apache Tomcat 9.0.13 to 9.0.62
Apache Tomcat 8.5.38 to 8.5.78

QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to a invalid URL and based on the response confirms the vulnerable instance of Apache Tomcat running on the host.

Successful exploitation of the vulnerability can allow an attacker to trigger a DoS via an Uncontrolled Resource Consumption

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Upgrade to the Apache Tomcat to the latest version of Apache Tomcat. Please refer to Apache Tomcat Security Advisory.

    CVEs related to QID 150531

    Software Advisories
    Advisory ID Software Component Link
    Apache Tomcat URL Logo lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcv