CVE Database
/

CVE-2022-23181

Back to search

CVE-2022-23181

Published: Jan 27, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

VendorProductVersions

Apache Software Foundation

Apache Tomcat

affected
Apache Tomcat 10.1 10.1.0-M1 to 10.1.0-M8
affected
Apache Tomcat 10.0 10.0.0-M5 to 10.0.14
affected
Apache Tomcat 9 9.0.35 to 9.0.56
affected
Apache Tomcat 8 8.5.55 to 8.5.73

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now