Re: Apache Tomcat EncryptInterceptor DoS CVE-2022-29885 vulnerability question

2022-05-31 Thread Mark Thomas
On 31/05/2022 16:17, DeHaven, Jacob wrote: In regards, to the Low: Apache Tomcat EncryptInterceptor DoSĀ  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29885 which is fixed in Apache Tomcat 9.0.63, it is being reporting as a Low vulnerability on the Apache Tomcat website but others (NIS

Re: Apache Tomcat EncryptInterceptor DoS CVE-2022-29885 vulnerability question

2022-05-31 Thread Christopher Schultz
Jacob, On 5/31/22 11:17, DeHaven, Jacob wrote: In regards, to the Low: Apache Tomcat EncryptInterceptor DoS http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29885 which is fixed in Apache Tomcat 9.0.63, it is being reporting as a Low vulnerability on the Apache Tomcat website but others (N

Apache Tomcat EncryptInterceptor DoS CVE-2022-29885 vulnerability question

2022-05-31 Thread DeHaven, Jacob
In regards, to the Low: Apache Tomcat EncryptInterceptor DoSĀ  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29885 which is fixed in Apache Tomcat 9.0.63, it is being reporting as a Low vulnerability on the Apache Tomcat website but others (NIST, Tenable) are reporting this vulnerability