Rewterz
Rewterz Threat Alert – Quantum Ransomware – Active IOCs
May 11, 2022
Rewterz
Rewterz Threat Advisory – Multiple SAP Host Agent and NetWeaver and ABAP Platform Vulnerabilities
May 12, 2022

Rewterz Threat Advisory – CVE-2022-29885 – Apache Tomcat Vulnerability

Severity

Medium

Analysis Summary

CVE-2022-29885

Apache Tomcat is vulnerable to a denial of service, caused by an use-after-free flaw in theEncryptInterceptor in an untrusted network. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.

Impact

  • Denial of Service

Indicators Of Compromise

CVE

  • CVE-2022-29885

Affected Vendors

  • Apache

Affected Products

  • Apache Tomcat 8.5.38
  • Apache Tomcat 9.0.13
  • Apache Tomcat 10.0.0-M1
  • Apache Tomcat 10.1.0-M1

Remediation

Upgrade to the latest version of Apache Tomcat, available from the Apache Website.

Apache Website