PT-2022-2876 · Apache+5 · Apache Tomcat+5

Published

2022-04-28

·

Updated

2026-05-18

·

CVE-2022-29885

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 10.1.0-M1 through 10.1.0-M14 Apache Tomcat versions 10.0.0-M1 through 10.0.20 Apache Tomcat versions 9.0.13 through 9.0.62 Apache Tomcat versions 8.5.38 through 8.5.78
Description The issue is related to the EncryptInterceptor in Apache Tomcat, which was incorrectly documented as enabling Tomcat clustering to run over an untrusted network. Although the EncryptInterceptor provides confidentiality and integrity protection, it does not protect against all risks associated with running over an untrusted network, particularly denial-of-service (DoS) risks. This could allow a remote attacker to cause a denial of service.
Recommendations For Apache Tomcat versions 10.1.0-M1 through 10.1.0-M14, update the documentation to reflect the correct capabilities of the EncryptInterceptor. For Apache Tomcat versions 10.0.0-M1 through 10.0.20, update the documentation to reflect the correct capabilities of the EncryptInterceptor. For Apache Tomcat versions 9.0.13 through 9.0.62, update the documentation to reflect the correct capabilities of the EncryptInterceptor. For Apache Tomcat versions 8.5.38 through 8.5.78, update the documentation to reflect the correct capabilities of the EncryptInterceptor. As a temporary workaround, consider restricting access to the EncryptInterceptor to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023_5708
ALSA-2023_5709
ALSA-2023_5710
ALSA-2023_5711
ALSA-2023_5712
ALSA-2023_5713
ALSA-2023_5721
ALSA-2023_5738
ALSA-2023_5749
ALSA-2023_5765
ALSA-2023_5837
ALSA-2023_5838
ALSA-2023_5849
ALSA-2023_5850
ALSA-2023_5863
ALSA-2023_5867
ALSA-2023_5869
ALSA-2023_5924
ALSA-2023_5928
ALSA-2023_5929
ALSA-2023_5989
ALSA-2023_6077
ALSA-2023_6120
ALSA-2023_6746
ALSA-2023_7205
ALSA-2024_1134
ALSA-2024_1444
ALSA-2024_5693
ALSA-2024_5694
ALSA-2025_11333
ALSA-2025_11335
ALSA-2025_16880
ALSA-2025_3645
ALSA-2025_3683
ALT-PU-2023-8058
ALT-PU-2025-2379
ALT-PU-2025-9146
BDU:2022-03434
BIT-TOMCAT-2022-29885
CLEANSTART-2026-AJ47488
CLEANSTART-2026-AM95501
CLEANSTART-2026-CD66042
CLEANSTART-2026-GR86205
CLEANSTART-2026-KB11938
CLEANSTART-2026-MR27796
CLEANSTART-2026-RH10099
CLEANSTART-2026-RK94800
CLEANSTART-2026-SJ80413
CLEANSTART-2026-TN71701
CLEANSTART-2026-UZ56639
CLEANSTART-2026-XI02879
CLEANSTART-2026-XP03839
CLEANSTART-2026-XP58111
CVE-2022-29885
DLA-3160-1
DSA-5265-1
GHSA-R84P-88G2-2VX2
MGASA-2023-0138
ROSA-SA-2023-2258
USN-6943-1

Affected Products

Alt Linux
Apache Tomcat
Astra Linux
Linuxmint
Red Os
Ubuntu