Security features bypass in Kotlin - CVE-2022-24329

 

Security features bypass in Kotlin - CVE-2022-24329

Published: February 8, 2022


Vulnerability identifier: #VU60367
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24329
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass certain security restrictions.

The vulnerability exists due to unspecified error, related to the ability to lock dependencies for Kotlin Multiplatform Gradle projects.



Affected software

Kotlin
IBM Cloud Transformation Advisor
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
Oracle Business Intelligence Enterprise Edition
IBM Business Automation Manager Open Editions
webMethods Integration Server
webMethods BPM
IBM Planning Analytics Workspace
OpenPages for IBM Cloud Pak for Data
Oracle Communications Pricing Design Center
Oracle Access Manager
Oracle Documaker
Oracle Communications Cloud Native Core Policy
watsonx.data
Event Streams

How to mitigate CVE-2022-24329

Install updates from vendor's website.

Kotlin - update to 1.6.0
IBM Cloud Transformation Advisor - update to 3.2.1
IBM Business Automation Manager Open Editions - update to 8.0.8
webMethods BPM - update to 11.1 Fix 1
Netcool Operations Insight - update to 1.6.6
watsonx.data - update to 2.0.3
IBM Planning Analytics Workspace - update to 2.0.83
OpenPages for IBM Cloud Pak for Data - update to 8.300.0
Event Streams - update to 11.4.0

External References

Related Security Bulletins