Vulnerability Description
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | >= 8.5.55, <= 8.5.73 |
| Oracle | Agile Engineering Data Management | 6.2.1.0 |
| Oracle | Communications Cloud Native Core Policy | 1.15.0 |
| Oracle | Financial Services Crime And Compliance Management Studio | 8.0.8.2.0 |
| Oracle | Managed File Transfer | 12.2.1.3.0 |
| Oracle | Mysql Enterprise Monitor | <= 8.0.29 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/l8x62p3k19yfcb208jo4zrb83k5mfwg9Mailing ListMitigationVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00029.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220217-0010/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5265Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
- https://lists.apache.org/thread/l8x62p3k19yfcb208jo4zrb83k5mfwg9Mailing ListMitigationVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00029.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220217-0010/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5265Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
FAQ
What is CVE-2022-23181?
CVE-2022-23181 is a vulnerability with a CVSS score of 7.0 (HIGH). The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed ...
How severe is CVE-2022-23181?
CVE-2022-23181 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23181?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Oracle Agile Engineering Data Management, Oracle Communications Cloud Native Core Policy, Oracle Financial Services Crime And Compliance Management Studio, Oracle Managed File Transfer.