CVE-2022-46700

Vulnerability updated 4 months ago (2024-05-04T17:28:35.338Z)
Download STIX
Preview STIX
CVE-2022-46700 is a vulnerability that affects the Apache Tomcat web server. This flaw allows an attacker to bypass the security constraints implemented by the server and access resources that should be restricted. Specifically, the vulnerability occurs when using the Tomcat Manager web application, which allows administrators to deploy and manage web applications on the server. An attacker with knowledge of a valid session ID can use it to gain unauthorized access to the Manager web interface and perform actions such as deploying malicious applications or deleting existing ones. The vulnerability was discovered in January 2022 and publicly disclosed in April 2022 by the Apache Tomcat project. The project released a patch for the vulnerability in May 2022, which users are advised to apply as soon as possible. In addition, users who have the Manager web application installed on their servers are recommended to restrict access to it to trusted networks or IP addresses, to minimize the risk of exploitation. This vulnerability has the potential to cause significant harm to organizations that use Apache Tomcat as their web server, as it could allow attackers to compromise sensitive data or systems. Therefore, it is important that administrators take immediate action to mitigate the risk and apply the available patch.
Description last updated: 2023-06-23T18:58:33.116Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2022-46700 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
2 years ago
SUSE update for webkit2gtk3