Apache Tomcat JsonErrorReportValve injection vulnerability (CVE-2022-45143) and Workload Automation AE
search cancel

Apache Tomcat JsonErrorReportValve injection vulnerability (CVE-2022-45143) and Workload Automation AE

book

Article ID: 264911

calendar_today

Updated On:

Products

Autosys Workload Automation

Issue/Introduction

Apache Tomcat JsonErrorReportValve injection vulnerability (CVE-2022-45143) was reported against the Tomcat releases distributed with AutoSys Servers.

 

Description:

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

Environment

Release : 12.0/12.1

Resolution

To address this vulnerability, update the bundled Tomcat to Tomcat 9.0.69 or higher using the steps provided here.

Tomcat 9 downloads are available here.