Vulnerability record · CVE-2022-29885 · published 12 May 2022
CVE-2022-29885: Apache Tomcat EncryptInterceptor documentation understates DoS risk
Apache · Tomcat
The documentation for Apache Tomcat's EncryptInterceptor incorrectly claimed it made Tomcat clustering safe to run over an untrusted network. In reality the interceptor provides confidentiality and integrity but does not protect against all risks, particularly denial-of-service. This matters because operators may have deployed clustering over untrusted networks believing it was fully protected.
Description
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityHigh CVSS (7.5) denial-of-service with no authentication required and very high EPSS, though no KEV listing or confirmed in-the-wild exploitation.
What it is
The documentation for Apache Tomcat's EncryptInterceptor incorrectly claimed it made Tomcat clustering safe to run over an untrusted network. In reality the interceptor provides confidentiality and integrity but does not protect against all risks, particularly denial-of-service. This matters because operators may have deployed clustering over untrusted networks believing it was fully protected.
Impact
An attacker on the network path can cause denial of service against Tomcat clustering traffic; there is no confidentiality or integrity impact per the CVSS vector.
Attack surface
Reachable over the network (AV:N) with no authentication or user interaction required (PR:N, UI:N), but only where Tomcat clustering with EncryptInterceptor is exposed to an untrusted network.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.73474, 99.4th percentile). A public Packet Storm proof-of-concept for Tomcat 10.1 DoS is referenced, indicating exploit code exists.
What to do
- Upgrade Tomcat to a release where the EncryptInterceptor documentation is corrected (beyond 10.1.0-M14, 10.0.20, 9.0.62, 8.5.78) and apply vendor patches referenced by Oracle and Debian advisories.
- Do not expose Tomcat clustering ports to untrusted networks; restrict them with firewall rules or network segmentation.
- Apply rate limiting and connection controls on clustering endpoints to blunt resource-exhaustion attempts.
- Review the Apache Tomcat mailing list mitigation guidance and adjust deployment assumptions about EncryptInterceptor accordingly.
Detection
- Monitor clustering port traffic for abnormal connection or packet volumes indicative of resource exhaustion.
- Alert on Tomcat process resource spikes (CPU, memory, thread counts) correlated with clustering traffic.
- Audit network exposure of Tomcat clustering ports to confirm they are not reachable from untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-29885 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-29885), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.