CVE-2022-23181

EUVD-2022-0937
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
TOCTOU
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 46%
Affected Products (NVD)
VendorProductVersion
apachetomcat
8.5.55 ≤
𝑥
≤ 8.5.73
apachetomcat
9.0.35 ≤
𝑥
≤ 9.0.56
apachetomcat
10.0.1 ≤
𝑥
≤ 10.0.14
apachetomcat
10.0.0:milestone10
apachetomcat
10.0.0:milestone5
apachetomcat
10.0.0:milestone6
apachetomcat
10.0.0:milestone7
apachetomcat
10.0.0:milestone8
apachetomcat
10.0.0:milestone9
apachetomcat
10.1.0:milestone1
apachetomcat
10.1.0:milestone2
apachetomcat
10.1.0:milestone3
apachetomcat
10.1.0:milestone4
apachetomcat
10.1.0:milestone5
apachetomcat
10.1.0:milestone6
apachetomcat
10.1.0:milestone7
apachetomcat
10.1.0:milestone8
oracleagile_engineering_data_management
6.2.1.0
oraclecommunications_cloud_native_core_policy
1.15.0
oraclefinancial_services_crime_and_compliance_management_studio
8.0.8.2.0
oraclefinancial_services_crime_and_compliance_management_studio
8.0.8.3.0
oraclemanaged_file_transfer
12.2.1.3.0
oraclemanaged_file_transfer
12.2.1.4.0
oraclemysql_enterprise_monitor
𝑥
≤ 8.0.29
debiandebian_linux
10.0
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tomcat9
bookworm
9.0.70-2
fixed
bullseye
9.0.43-2~deb11u10
fixed
bullseye (security)
9.0.43-2~deb11u10
fixed
sid
9.0.95-1
fixed
stretch
postponed
trixie
9.0.95-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tomcat8
bionic
Fixed 8.5.39-1ubuntu1~18.04.3+esm2
released
trusty
ignored
xenial
Fixed 8.0.32-1ubuntu1.13+esm1
released
tomcat9
bionic
Fixed 9.0.16-3ubuntu0.18.04.2+esm2
released
focal
Fixed 9.0.31-1ubuntu0.6
released
impish
ignored
jammy
not-affected
kinetic
ignored
lunar
ignored
mantic
ignored
noble
not-affected
trusty
ignored
xenial
ignored