Deserialization of Untrusted Data in Chainsaw - CVE-2022-23307,CVE-2020-9493
Published: January 18, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
IBM Cloud Pak for Multicloud Management
Traffix SDC
IBM Sterling Order Management
Cúram Social Program Management (SPM)
IBM OpenPages with Watson
Datacap
IBM Security Verify Information Queue
IBM Cloud Pak for Watson AIOps
DevOps
Crypto Hardware Initialization and Maintenance (CHIM)
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
CentOS
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
openEuler
Red Hat Software Collections
Apache Log4j
Jazz for Service Management
Spectrum Discover
IBM Sterling Partner Engagement Manager
JBoss A-MQ
Splunk AppDynamics Database Agent
IBM Cloud Pak for Data System
Log Analysis
Netcool Operations Insight
IBM Security Access Manager for Enterprise Single-Sign On
Security Director Insights
log4j (Red Hat package)
eap7-jboss-server-migration (Red Hat package)
eap7-wildfly-elytron (Red Hat package)
eap7-undertow (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
ovirt-engine (Red Hat package)
rhvm-branding-rhv (Red Hat package)
eap7-hibernate (Red Hat package)
tomcat7 (Red Hat package)
eap7-wildfly (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
tomcat8 (Red Hat package)
liblog4j1.2-java (Ubuntu package)
eap7-jboss-annotations (Red Hat package)
eap7-wildfly-openssl-el7 (Red Hat package)
eap7-wildfly-openssl-el8 (Red Hat package)
parfait
parfait-examples
parfait-javadoc
pcp-parfait-agent
eap7-yasson (Red Hat package)
log4j-jboss-logmanager (Red Hat package)
eap7-log4j-jboss-logmanager (Red Hat package)
log4j-manual
log4j
log4j-eap6 (Red Hat package)
apache-log4j1.2 (Ubuntu package)
log4j12-javadoc
log4j12
log4j12-manual
log4j-javadoc
rh-maven36-log4j12 (Red Hat package)
log4j12-help
eap7-xom (Red Hat package)
eap7-h2database (Red Hat package)
eap7-avro (Red Hat package)
eap7-jboss-marshalling (Red Hat package)
eap7-wildfly-openssl (Red Hat package)
eap7-xml-security (Red Hat package)
eap7-wss4j (Red Hat package)
eap7-xalan-j2 (Red Hat package)
eap7-activemq-artemis (Red Hat package)
eap7-log4j (Red Hat package)
eap7-jboss-vfs (Red Hat package)
eap7-hal-console (Red Hat package)
eap7-apache-cxf (Red Hat package)
snmp4j (Red Hat package)
eap7-ecj (Red Hat package)
eap7-jbossws-cxf (Red Hat package)
eap7-narayana (Red Hat package)
eap7-objectweb-asm (Red Hat package)
eap7-infinispan (Red Hat package)
rh-sso7-keycloak (Red Hat package)
AMQ Streams
Fuse
JBoss Enterprise Application Platform
IBM WebSphere Application Server
IBM WebSphere Application Server Liberty
IBM Db2 Web Query for i
IBM Content Navigator
JBoss Web Server
Red Hat Virtualization Manager
IBM App Connect for Healthcare
JBoss Data Grid
IBM Qradar SIEM
IBM Cognos Command Center
JBoss Data Virtualization
Red Hat Single Sign-On
IBM Cloud Pak System
How to mitigate CVE-2022-23307,CVE-2020-9493
Jazz for Service Management - update to 1.1.3.25
log4j (Red Hat package) - addressed in versions 1.2.17-17.el7_3, 1.2.17-18.el7_4
AMQ Streams - addressed in versions 1.6.7, 2.0.1
eap7-jboss-server-migration (Red Hat package) - addressed in versions 1.7.2-12.Final_redhat_00013.1.el7eap, 1.10.0-15.Final_redhat_00014.1.el7eap, 1.10.0-15.Final_redhat_00014.1.el8eap
eap7-wildfly-elytron (Red Hat package) - addressed in versions 1.15.11-1.Final_redhat_00002.1.el7eap, 1.15.11-1.Final_redhat_00002.1.el8eap
Spectrum Discover - update to 2.0.4.5
eap7-undertow (Red Hat package) - addressed in versions 2.2.16-1.Final_redhat_00001.1.el7eap, 2.2.16-1.Final_redhat_00001.1.el8eap
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008 LA2, 3.2.0 IF004
JBoss Web Server - update to 3.1.14
eap7-jboss-xnio-base (Red Hat package) - addressed in versions 3.7.13-1.Final_redhat_00001.1.el7eap, 3.8.6-1.Final_redhat_00001.1.el7eap, 3.8.6-1.Final_redhat_00001.1.el8eap
ovirt-engine (Red Hat package) - update to 4.4.10.6-0.1.el8ev
rhvm-branding-rhv (Red Hat package) - update to 4.4.10-1.el8ev
eap7-hibernate (Red Hat package) - addressed in versions 5.3.25-1.Final_redhat_00002.1.el7eap, 5.3.25-1.Final_redhat_00002.1.el8eap
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
Fuse - addressed in versions 6.3.20, 7.10.1
JBoss A-MQ - update to 6.3.20
JBoss Enterprise Application Platform - addressed in versions 7.3.11, 7.4.4
JBoss Data Virtualization - addressed in versions 6.4.8.SP1, 6.4.8 SP2
tomcat7 (Red Hat package) - update to 7.0.70-46.ep7.el7
JBoss Data Grid - update to 7.3.9
Red Hat Single Sign-On - addressed in versions 7.4.10, 7.5.1
eap7-wildfly (Red Hat package) - addressed in versions 7.3.11-4.GA_redhat_00002.1.el7eap, 7.4.4-3.GA_redhat_00011.1.el7eap, 7.4.4-3.GA_redhat_00011.1.el8eap
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF01
tomcat8 (Red Hat package) - update to 8.0.36-49.ep7.el7
IBM OpenPages with Watson - addressed in versions 8.1.0.2.3, 8.2.0.4.3
Datacap - update to 9.1.10
IBM Security Verify Information Queue - update to 10.0.3
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF15
IBM WebSphere Application Server Liberty - update to 22.0.0.1
Splunk AppDynamics Database Agent - update to 26.1.0
liblog4j1.2-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2.17-8+deb10u1ubuntu0.2, 1.2.17-9ubuntu0.2
eap7-jboss-annotations (Red Hat package) - update to api_1.3_spec-2.0.1-4.Final_redhat_00001.1.el7eap
eap7-wildfly-openssl-el7 (Red Hat package) - update to x86_64-2.2.0-2.Final_redhat_00002.1.el7eap
eap7-wildfly-openssl-el8 (Red Hat package) - update to x86_64-2.2.0-2.Final_redhat_00002.1.el8eap
parfait - update to 0.5.4-4
parfait-examples - update to 0.5.4-4
parfait-javadoc - update to 0.5.4-4
pcp-parfait-agent - update to 0.5.4-4
IBM Cloud Pak for Data System - update to 1.0.7.8
eap7-yasson (Red Hat package) - addressed in versions 1.0.10-1.redhat_00001.1.el7eap, 1.0.10-1.redhat_00001.1.el8eap
log4j-jboss-logmanager (Red Hat package) - addressed in versions 1.1.4-3.Final_redhat_00002.1.ep6.el6, 1.1.4-3.Final_redhat_00002.1.ep6.el7
eap7-log4j-jboss-logmanager (Red Hat package) - addressed in versions 1.2.2-1.Final_redhat_00002.1.el7eap, 1.2.2-1.Final_redhat_00002.1.el8eap, 1.2.2-2.Final_redhat_00002.1.el7eap
log4j-manual - addressed in versions 1.2.15-126.9.1, 1.2.17-5.9.1
log4j - addressed in versions 1.2.15-126.9.1, 1.2.17-5.9.1
log4j-eap6 (Red Hat package) - addressed in versions 1.2.17-3.redhat_00008.1.ep6.el6, 1.2.17-3.redhat_00008.1.ep6.el7
apache-log4j1.2 (Ubuntu package) - update to 1.2.17-4ubuntu3+esm2
log4j12-javadoc - update to 1.2.17-4.9.1
log4j12 - update to 1.2.17-4.9.1
log4j12-manual - update to 1.2.17-4.9.1
log4j - update to 1.2.17-16.14
log4j - update to 1.2.17-18
log4j-javadoc - update to 1.2.17-18
log4j-manual - update to 1.2.17-18
rh-maven36-log4j12 (Red Hat package) - update to 1.2.17-23.4.el7
log4j12-help - update to 1.2.17-25
log4j12 - update to 1.2.17-25
eap7-xom (Red Hat package) - addressed in versions 1.3.7-1.redhat_00001.1.el7eap, 1.3.7-1.redhat_00001.1.el8eap
Log Analysis - update to 1.3.7.2
eap7-h2database (Red Hat package) - update to 1.4.197-3.redhat_00004.1.el7eap
Netcool Operations Insight - update to 1.6.7
eap7-avro (Red Hat package) - update to 1.7.6-8.redhat_00003.1.el7eap
eap7-jboss-marshalling (Red Hat package) - update to 2.0.15-1.Final_redhat_00001.1.el7eap
eap7-wildfly-openssl (Red Hat package) - addressed in versions 2.2.0-3.Final_redhat_00002.1.el7eap, 2.2.0-3.Final_redhat_00002.1.el8eap
eap7-xml-security (Red Hat package) - update to 2.2.3-2.redhat_00001.1.el7eap
eap7-wss4j (Red Hat package) - update to 2.3.3-2.redhat_00001.1.el7eap
IBM Cloud Pak System - update to 2.3.3.4
eap7-xalan-j2 (Red Hat package) - update to 2.7.1-38.redhat_00015.1.el7eap
eap7-activemq-artemis (Red Hat package) - addressed in versions 2.16.0-7.redhat_00034.1.el7eap, 2.16.0-7.redhat_00034.1.el8eap
eap7-log4j (Red Hat package) - addressed in versions 2.17.1-1.redhat_00001.1.el7eap, 2.17.1-1.redhat_00001.1.el8eap
eap7-jboss-vfs (Red Hat package) - addressed in versions 3.2.16-1.Final_redhat_00001.1.el7eap, 3.2.16-1.Final_redhat_00001.1.el8eap
eap7-hal-console (Red Hat package) - addressed in versions 3.3.9-1.Final_redhat_00001.1.el7eap, 3.3.9-1.Final_redhat_00001.1.el8eap
eap7-apache-cxf (Red Hat package) - update to 3.4.10-1.SP1_redhat_00001.1.el7eap
snmp4j (Red Hat package) - update to 3.6.4-0.1.el8ev
IBM Cloud Pak for Watson AIOps - update to 3.7.1
eap7-ecj (Red Hat package) - addressed in versions 3.26.0-1.redhat_00002.1.el7eap, 3.26.0-1.redhat_00002.1.el8eap
eap7-jbossws-cxf (Red Hat package) - addressed in versions 5.4.4-1.Final_redhat_00001.1.el7eap, 5.4.4-1.Final_redhat_00001.1.el8eap
eap7-narayana (Red Hat package) - addressed in versions 5.11.4-1.Final_redhat_00001.1.el7eap, 5.11.4-1.Final_redhat_00001.1.el8eap
DevOps - update to 7.0.0.2
IBM Security Access Manager for Enterprise Single-Sign On - update to 8.2.2 Fix Pack 15
eap7-objectweb-asm (Red Hat package) - addressed in versions 9.1.0-1.redhat_00002.1.el7eap, 9.1.0-1.redhat_00002.1.el8eap
eap7-infinispan (Red Hat package) - addressed in versions 11.0.15-1.Final_redhat_00001.1.el7eap, 11.0.15-1.Final_redhat_00001.1.el8eap
rh-sso7-keycloak (Red Hat package) - addressed in versions 15.0.4-1.redhat_00003.1.el7sso, 15.0.4-1.redhat_00003.1.el8sso
Security Director Insights - update to 23.1R1
External References
Related Security Bulletins
- Remote code execution in Apache Chainsaw
- Deserialization of untrusted data in Apache Log4j Chainsaw component
- Red Hat Enterprise Linux 8.4 update for the parfait:0.5 module
- Red Hat Enterprise Linux 8 update for the parfait:0.5 module
- Red Hat Enterprise Linux 8.2 update for the parfait:0.5 module
- Red Hat Enterprise Linux 8.1 update for the parfait:0.5 module
- Multiple vulnerabilities in IBM Db2 Web Query for i
- Multiple vulnerabilities in Red Hat Data Grid
- Red Hat Software Collections update for rh-maven36-log4j12
- Red Hat JBoss Enterprise Application Platform 7.4 update for Apache Log4j
- Red Hat JBoss Enterprise Application Platform 6.4 update for Apache Log4j
- CentOS 7 update for log4j
- Red Hat Single Sign-On update for Apache Log4j
- Multiple vulnerabilities in Red Hat Single Sign-On 7.5 for Red Hat Enterprise Linux 8
- Multiple vulnerabilities in Red Hat Single Sign-On for Red Hat Enterprise Linux 7
- Multiple vulnerabilities in Red Hat Single Sign-On
- Red Hat Enterprise Linux Server 7 update for log4j
- Multiple vulnerabilities in Red Hat AMQ Streams 1.6
- Multiple vulnerabilities in Red Hat AMQ Streams 2.0
- Multiple vulnerabilities in Red Hat Virtualization Manager
- Multiple vulnerabilities in Red Hat JBoss Data Virtualization
- Multiple vulnerabilities in Red Hat JBoss Data Virtualization
- Multiple vulnerabilities in Red Hat JBoss Web Server 3.1
- Multiple vulnerabilities in Red Hat JBoss Fuse and A-MQ
- Remote code execution in IBM App Connect for Healthcare
- Multiple vulnerabilities in IBM WebSphere Application Server
- Multiple vulnerabilities in Red Hat Fuse 7.10
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- JBoss Enterprise Application Platform 7.4 for RHEL 8 update for log4j
- JBoss Enterprise Application Platform 7.4 for RHEL 7 update for log4j
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM Security Verify Information Queue
- Remote code execution in IBM OpenPages with Watson
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in IBM Spectrum Discover
- Remote code execution in IBM Sterling Order Management
- SUSE update for log4j
- SUSE update for log4j
- SUSE update for log4j12
- Deserialization of untrusted data in IBM Cloud Pak for Data System (CPDS)
- Ubuntu update for apache-log4j1.2
- Amazon Linux AMI update for log4j
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- F5 Traffix SDC update for Apache Log4j Chainsaw
- Multiple vulnerabilities in IBM Security Access Manager for Enterprise Single Sign-On
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Networks Security Director Insights
- Gentoo update for Apache Log4j
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- openEuler update for log4j12
- openEuler 22.03 LTS update for log4j12
- Multiple vulnerabilities in IBM DevOps Release
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7
- Anolis OS update for parfait:0.5 module
- Anolis OS update for log4j
- Ubuntu update for apache-log4j1.2
- Multiple vulnerabilities in IBM Jazz for Service Management
- Multiple vulnerabilities in Crypto Hardware Initialization and Maintenance (CHIM) as shipped with IBM Common Cryptographic Architecture (CCA)
- Multiple vulnerabilities in IBM Cúram Social Program Management (SPM)
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager Essentials Edition
- Multiple vulnerabilities in IBM Datacap
- Splunk AppDynamics Database Agent update for third-party components
- Multiple vulnerabilities in IBM Content Navigator