Apache Tomcat request smuggling vulnerability (CVE-2022-42252) and Workload Automation AE
search cancel

Apache Tomcat request smuggling vulnerability (CVE-2022-42252) and Workload Automation AE

book

Article ID: 264913

calendar_today

Updated On:

Products

Autosys Workload Automation

Issue/Introduction

Apache Tomcat request smuggling vulnerability (CVE-2022-42252) was reported against the Tomcat releases distributed with AutoSys Servers.

 

Description:

If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.

Environment

Release : 12.0/12.1

Resolution

To address this vulnerability, update the bundled Tomcat to Tomcat 9.0.68 or higher using the steps provided here.

Tomcat 9 downloads are available here.