Tracker / CVE-2022-29885
CVE-2022-29885
Alta 7.5
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
Prodotti e versioni affette
| apache | tomcat |
|---|---|
| apache | tomcat · 10.0.0 → 10.0.20 |
| apache | tomcat · 8.5.38 → 8.5.78 |
| apache | tomcat · 9.0.13 → 9.0.62 |
| debian | debian_linux |
| oracle | hospitality_cruise_shipboard_property_management_system |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.