HTTP: Apache Tomcat EncryptInterceptor Denial Of Service

This signature detects attempts to exploit a known vulnerability against Apache Tomcat EncryptInterceptor. A successful attack can result in a denial-of-service condition.

Extended Description

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

Affected Products

Debian debian_linux

References

CVE: CVE-2022-29885

Short Name
HTTP:APACHE:ENCRYPT-INTRCPT-DOS
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Apache CVE-2022-29885 Denial EncryptInterceptor Of Service Tomcat
Release Date
01/04/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3666
Port
TCP/4000
False Positive
Unknown
Vendors

Apache

Oracle

Debian

Found a potential security threat?