High severity7.5NVD Advisory· Published May 12, 2022· Updated Jun 17, 2026
CVE-2022-29885
CVE-2022-29885
Description
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:tomcatMaven | >= 10.1.0-M1, < 10.1.0-M15 | 10.1.0-M15 |
org.apache.tomcat:tomcatMaven | >= 10.0.0-M1, < 10.0.21 | 10.0.21 |
org.apache.tomcat:tomcatMaven | >= 9.0.13, < 9.0.63 | 9.0.63 |
org.apache.tomcat:tomcatMaven | >= 8.5.38, < 8.5.79 | 8.5.79 |
Affected products
21cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*range: >=8.5.38,<=8.5.78
- cpe:2.3:a:apache:tomcat:10.1.0:milestone10:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone11:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone12:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone13:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone14:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone2:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone3:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone4:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone5:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone6:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone7:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone8:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone9:*:*:*:*:*:*
- cpe:2.3:a:oracle:hospitality_cruise_shipboard_property_management_system:20.2.1:*:*:*:*:*:*:*
- osv-coords2 versions
>= 8.5.38, < 8.5.79+ 1 more
- (no CPE)range: >= 8.5.38, < 8.5.79
- (no CPE)range: >= 10.1.0-M1, < 10.1.0-M15
- Apache Software Foundation/Apache Tomcatv5Range: Apache Tomcat 10.1 10.1.0-M1 to 10.1.0-M14
Patches
Vulnerability mechanics
References
13- www.oracle.com/security-alerts/cpujul2022.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-r84p-88g2-2vx2ghsaADVISORY
- lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcvnvdMailing ListMitigationVendor AdvisoryWEB
- lists.debian.org/debian-lts-announce/2022/10/msg00029.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-29885ghsaADVISORY
- security.netapp.com/advisory/ntap-20220629-0002/nvdThird Party Advisory
- www.debian.org/security/2022/dsa-5265nvdThird Party AdvisoryWEB
- github.com/apache/tomcat/commit/0fa7721f11d565a2cd2e44366c388ad6a3e6357dghsaWEB
- github.com/apache/tomcat/commit/36826ea638457d7e17876a70f89cb435b6db0d91ghsaWEB
- github.com/apache/tomcat/commit/b679bc627f5a4ea6510af95adfb7476b07eba890ghsaWEB
- github.com/apache/tomcat/commit/eaafd28296c54d983e28a47953c1f5cb2c334f48ghsaWEB
- security.netapp.com/advisory/ntap-20220629-0002ghsaWEB
- packetstormsecurity.com/files/171728/Apache-Tomcat-10.1-Denial-Of-Service.htmlnvd
News mentions
0No linked articles in our index yet.