Incorrect Regular Expression in Spring Framework - CVE-2022-22950

 

Incorrect Regular Expression in Spring Framework - CVE-2022-22950

Published: March 31, 2022


Vulnerability identifier: #VU61760
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22950
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due improper input validation when processing SpEL expressions. A remote attacker can send a specially crafted HTTP request to the affected application and perform a denial of service (DoS) attack.


Affected software

Spring Framework
IBM i Modernization Engine for Lifecycle Integration
IBM Planning Analytics Workspace
Dell Policy Manager for Secure Connect Gateway (SCG)
Storage Copy Data Management
IBM Tivoli Netcool Configuration Manager
IBM OpenPages with Watson
Storage Protect Plus Server
rhv-log-collector-analyzer (Red Hat package)
ovirt-engine-ui-extensions (Red Hat package)
ovirt-web-ui (Red Hat package)
ovirt-engine-dwh (Red Hat package)
ovirt-engine (Red Hat package)
rhvm-branding-rhv (Red Hat package)
apache-commons-compress (Red Hat package)
springframework-orm
springframework-aop
springframework-beans
springframework-context
springframework-expression
springframework-help
springframework-instrument
springframework-jdbc
springframework-jms
springframework-orm-hibernate4
springframework-oxm
springframework-tx
springframework-web
springframework
ovirt-log-collector (Red Hat package)
ovirt-dependencies (Red Hat package)
postgresql-jdbc (Red Hat package)
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
IBM SPSS Collaboration and Deployment Services
IBM Common Licensing
Autodesk Infraworks
IBM MaaS360 Mobile Enterprise Gateway
IBM MaaS360 Cloud Extender Agent
IBM Sterling B2B Integrator
IBM Tivoli Monitoring
EMC NetWorker Server
IBM Db2 Web Query for i
Red Hat Virtualization Manager
Unified Data Protection
IBM Cognos Controller
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
RSA Identity Governance and Lifecycle
Enterprise Manager for Oracle Database
openEuler
watsonx.data
Library Support for Spring
IBM MaaS360 VPN Module

How to mitigate CVE-2022-22950

Install updates from vendor's website.

Spring Framework - update to 5.3.17
IBM i Modernization Engine for Lifecycle Integration - update to 1.0.1
rhv-log-collector-analyzer (Red Hat package) - update to 1.0.14-1.el8ev
ovirt-engine-ui-extensions (Red Hat package) - update to 1.3.4-1.el8ev
ovirt-web-ui (Red Hat package) - update to 1.9.0-1.el8ev
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.9
ovirt-engine-dwh (Red Hat package) - update to 4.5.3-1.el8ev
ovirt-engine (Red Hat package) - update to 4.5.1.2-0.11.el8ev
rhvm-branding-rhv (Red Hat package) - update to 4.5.0-1.el8ev
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.12.00.00
Dell Secure Connect Gateway - update to 5.16
Unified Data Protection - update to 9.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.0
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
apache-commons-compress (Red Hat package) - update to 1.21-1.2.el8ev
watsonx.data - update to 2.1.1
Storage Copy Data Management - update to 2.2.23.0
Library Support for Spring - update to 2.7.29
IBM MaaS360 Mobile Enterprise Gateway - update to 2.106.500
IBM MaaS360 VPN Module - update to 2.106.500
IBM MaaS360 Cloud Extender Agent - update to 2.106.500.011
springframework-orm - update to 3.2.18-14
springframework-aop - update to 3.2.18-14
springframework-beans - update to 3.2.18-14
springframework-context - update to 3.2.18-14
springframework-expression - update to 3.2.18-14
springframework-help - update to 3.2.18-14
springframework-instrument - update to 3.2.18-14
springframework-jdbc - update to 3.2.18-14
springframework-jms - update to 3.2.18-14
springframework-orm-hibernate4 - update to 3.2.18-14
springframework-oxm - update to 3.2.18-14
springframework-tx - update to 3.2.18-14
springframework-web - update to 3.2.18-14
springframework - update to 3.2.18-14
ovirt-log-collector (Red Hat package) - update to 4.4.6-1.el8ev
ovirt-dependencies (Red Hat package) - update to 4.5.2-1.el8ev
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.6, 6.1.1.2, 6.1.2.0
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 12
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.18
IBM OpenPages with Watson - addressed in versions 8.2.0.4.7, 8.2.0.5, 8.3.0.2
Storage Protect Plus Server - update to 10.1.16.1
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
EMC NetWorker Server - update to 19.7.0.0
postgresql-jdbc (Red Hat package) - update to 42.2.14-1.el8ev

External References

Related Security Bulletins