HIGH · 7.0

CVE-2022-23181

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed ...

Vulnerability Description

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

CVSS Score

7.0

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ApacheTomcat>= 8.5.55, <= 8.5.73
OracleAgile Engineering Data Management6.2.1.0
OracleCommunications Cloud Native Core Policy1.15.0
OracleFinancial Services Crime And Compliance Management Studio8.0.8.2.0
OracleManaged File Transfer12.2.1.3.0
OracleMysql Enterprise Monitor<= 8.0.29
DebianDebian Linux10.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-23181?

CVE-2022-23181 is a vulnerability with a CVSS score of 7.0 (HIGH). The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed ...

How severe is CVE-2022-23181?

CVE-2022-23181 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-23181?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Oracle Agile Engineering Data Management, Oracle Communications Cloud Native Core Policy, Oracle Financial Services Crime And Compliance Management Studio, Oracle Managed File Transfer.