[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2022-1572 --- tomcat8

ID: oval:org.secpod.oval:def:1601521Date: (C)2022-03-11   (M)2023-01-09
Class: PATCHFamily: unix




The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore

Platform:
Amazon Linux AMI
Product:
tomcat8
Reference:
ALAS-2022-1572
CVE-2022-23181
CVE    1
CVE-2022-23181
CPE    2
cpe:/o:amazon:linux
cpe:/a:apache:tomcat8

© SecPod Technologies