PT-2022-5376 · Apache+6 · Apache Tomcat+6

Published

2022-01-20

·

Updated

2026-05-18

·

CVE-2022-23181

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 8.5.55 through 8.5.73 Apache Tomcat versions 9.0.35 through 9.0.56 Apache Tomcat versions 10.0.0-M5 through 10.0.14 Apache Tomcat versions 10.1.0-M1 through 10.1.0-M8
Description The issue is related to a time of check, time of use vulnerability in Apache Tomcat. This vulnerability can be exploited by a local attacker to perform actions with the privileges of the user that the Tomcat process is using. The issue is only exploitable when Tomcat is configured to persist sessions using the FileStore. Exploitation of this vulnerability may allow an attacker to bypass security restrictions and elevate privileges, executing code with the privileges of the Tomcat process.
Recommendations For Apache Tomcat versions 8.5.55 through 8.5.73, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 9.0.35 through 9.0.56, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 10.0.0-M5 through 10.0.14, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 10.1.0-M1 through 10.1.0-M8, update to a version outside of this range to resolve the issue. As a temporary workaround, consider configuring Tomcat to not persist sessions using the FileStore until a patch is available.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2165
ALT-PU-2022-3296
ALT-PU-2025-9146
BDU:2022-06690
BIT-TOMCAT-2022-23181
CLEANSTART-2026-AJ47488
CLEANSTART-2026-AM95501
CLEANSTART-2026-CD66042
CLEANSTART-2026-GR86205
CLEANSTART-2026-KB11938
CLEANSTART-2026-MR27796
CLEANSTART-2026-RH10099
CLEANSTART-2026-RK94800
CLEANSTART-2026-SJ80413
CLEANSTART-2026-TN71701
CLEANSTART-2026-UZ56639
CLEANSTART-2026-XI02879
CLEANSTART-2026-XP03839
CLEANSTART-2026-XP58111
CVE-2022-23181
DLA-3160-1
DSA-5265-1
GHSA-9F3J-PM6F-9FM5
MGASA-2023-0138
OESA-2022-1537
OESA-2022-2064
OPENSUSE-SU-2022:0818-1
OPENSUSE-SU-2022_0818-1
OPENSUSE-SU-2024:11864-1
OPENSUSE-SU-2024:13441-1
RHSA-2022:7272
ROSA-SA-2023-2258
SUSE-SU-2022:0694-1
SUSE-SU-2022:0695-1
SUSE-SU-2022:0784-1
SUSE-SU-2022:0818-1
SUSE-SU-2022_0694-1
SUSE-SU-2022_0695-1
SUSE-SU-2022_0784-1
SUSE-SU-2022_0818-1
SUSE-SU-2026:1058-1
USN-6943-1

Affected Products

Alt Linux
Apache Tomcat
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu