CVE-2022-25762 is a high-severity vulnerability affecting Apache Tomcat versions 8.5.0 to 8.5.75 and 9.0.0.M1 to 9.0.20, as well as Oracle Agile PLM. It arises when a web application concurrently sends a WebSocket message and closes the connection, potentially leading to a pooled object being used twice. This can result in subsequent connections receiving incorrect data or other errors. With a CVSS score of 8.6, it has a network attack vector and low attack complexity, allowing for high confidentiality and low integrity/availability impacts. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.5.0, < 8.5.76CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.21CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
9.3.6CPE matchmatch criteria | cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.