QID 730504

Date Published: 2022-05-31

QID 730504: Apache Tomcat Improper Resource Release Vulnerability (CVE-2022-25762)

Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.

A vulnerability in Apache Tomcat results in Improper Resource Shutdown

Affected Versions:
Apache Tomcat 9.0.0.M1 to 9.0.20
Apache Tomcat 8.5.0 to 8.5.75

QID Detection Logic (Unauthenticated):
The QID checks for vulnerable version by sending a GET /QUALYS730242 HTTP/1.0 request which helps in retrieving the installed version of Apache Tomcat in the banner of the response.

A successful exploit may cause Improper Resource Shutdown

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to the Apache Tomcat to the latest version of Apache Tomcat. Please refer to Apache Tomcat Security Advisory.

    CVEs related to QID 730504

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-25762 URL Logo lists.apache.org/thread/6ckmjfb1k61dyzkto9vm2k5jvt4o7w7c