---
id: CVE-2022-29885
title: >-
  The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to
  10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor
  incorrectly stated it enabled Tomcat clustering to run over an untrusted
  network
summary: >-
  The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to
  10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor
  incorrectly stated it enabled Tomcat clustering to run over an untrusted
  network. This was…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: apache
product: tomcat
affected:
  - 'tomcat >= 8.5.38, <= 8.5.78'
  - 'tomcat >= 9.0.13, <= 9.0.62'
  - 'tomcat >= 10.0.0, <= 10.0.20'
  - tomcat = 10.1.0
  - debian_linux = 10.0
  - debian_linux = 11.0
  - hospitality_cruise_shipboard_property_management_system = 20.2.1
published: '2022-05-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:20.840'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-29885'
references:
  - url: >-
      http://packetstormsecurity.com/files/171728/Apache-Tomcat-10.1-Denial-Of-Service.html
    label: security@apache.org
  - url: 'https://lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcv'
    label: security@apache.org
  - url: 'https://lists.debian.org/debian-lts-announce/2022/10/msg00029.html'
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20220629-0002/'
    label: security@apache.org
  - url: 'https://www.debian.org/security/2022/dsa-5265'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security@apache.org
  - url: >-
      http://packetstormsecurity.com/files/171728/Apache-Tomcat-10.1-Denial-Of-Service.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.apache.org/thread/2b4qmhbcyqvc7dyfpjyx54c03x65vhcv'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2022/10/msg00029.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220629-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2022/dsa-5265'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.73474
epssPercentile: 0.99457
exploits:
  exploitdb: true
  github: 2
  githubRepos:
    - 'https://github.com/quynhlab/CVE-2022-29885'
    - 'https://github.com/iveresk/CVE-2022-29885'
  checkedAt: '2026-10-08T23:17:21.758Z'
exploitAvailable: true
ingestedAt: '2026-10-08T23:16:47.343Z'
---

## Overview

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

## Affected

- `tomcat >= 8.5.38, <= 8.5.78`
- `tomcat >= 9.0.13, <= 9.0.62`
- `tomcat >= 10.0.0, <= 10.0.20`
- `tomcat = 10.1.0`
- `debian_linux = 10.0`
- `debian_linux = 11.0`
- `hospitality_cruise_shipboard_property_management_system = 20.2.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
