Deserialization of Untrusted Data in H2 Database - CVE-2022-23221
Published: April 6, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data within jdbc:h2:mem. A remote attacker can pass specially crafted JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
Ubuntu
Oracle Communications Cloud Native Core Console
Oracle Healthcare Translational Research
JBoss Enterprise Application Platform
Oracle SOA Suite
eap7-jboss-annotations (Red Hat package)
eap7-log4j-jboss-logmanager (Red Hat package)
eap7-h2database (Red Hat package)
h2database (Debian package)
libh2-java (Ubuntu package)
eap7-jboss-server-migration (Red Hat package)
eap7-avro (Red Hat package)
eap7-bouncycastle (Red Hat package)
eap7-jboss-marshalling (Red Hat package)
eap7-xml-security (Red Hat package)
eap7-wss4j (Red Hat package)
eap7-xalan-j2 (Red Hat package)
eap7-jackson-databind (Red Hat package)
eap7-apache-cxf (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
eap7-wildfly (Red Hat package)
watsonx.data
How to mitigate CVE-2022-23221
JBoss Enterprise Application Platform - addressed in versions 7.1.8, 7.3.11, 7.4.5
eap7-jboss-annotations (Red Hat package) - update to api_1.3_spec-2.0.1-4.Final_redhat_00001.1.el7eap
eap7-log4j-jboss-logmanager (Red Hat package) - update to 1.2.2-2.Final_redhat_00002.1.el7eap
eap7-h2database (Red Hat package) - addressed in versions 1.4.197-2.redhat_00005.1.ep7.el7, 1.4.197-3.redhat_00004.1.el7eap
h2database (Debian package) - addressed in versions 1.4.197-4+deb10u1, 1.4.197-4+deb11u1
libh2-java (Ubuntu package) - addressed in versions 1.4.197-4+deb10u1build0.20.04.1, 1.4.197-4+deb10u1build0.21.10.1
eap7-jboss-server-migration (Red Hat package) - update to 1.7.2-12.Final_redhat_00013.1.el7eap
eap7-avro (Red Hat package) - addressed in versions 1.7.6-2.redhat_00003.1.ep7.el7, 1.7.6-8.redhat_00003.1.el7eap
eap7-bouncycastle (Red Hat package) - update to 1.68.0-1.redhat_00005.1.ep7.el7
watsonx.data - update to 2.0.2
eap7-jboss-marshalling (Red Hat package) - addressed in versions 2.0.15-1.Final_redhat_00001.1.el7eap, 2.0.15-1.Final_redhat_00001.1.ep7.el7
eap7-xml-security (Red Hat package) - update to 2.2.3-2.redhat_00001.1.el7eap
eap7-wss4j (Red Hat package) - update to 2.3.3-2.redhat_00001.1.el7eap
eap7-xalan-j2 (Red Hat package) - addressed in versions 2.7.1-26.redhat_00015.1.ep7.el7, 2.7.1-38.redhat_00015.1.el7eap
eap7-jackson-databind (Red Hat package) - update to 2.8.11.6-1.SP1_redhat_00001.1.ep7.el7
eap7-apache-cxf (Red Hat package) - addressed in versions 3.1.16-3.SP1_redhat_00001.1.ep7.el7, 3.4.10-1.SP1_redhat_00001.1.el7eap
eap7-jboss-xnio-base (Red Hat package) - addressed in versions 3.5.10-1.Final_redhat_00001.1.ep7.el7, 3.7.13-1.Final_redhat_00001.1.el7eap
eap7-wildfly (Red Hat package) - addressed in versions 7.1.8-2.GA_redhat_00002.1.ep7.el7, 7.3.11-4.GA_redhat_00002.1.el7eap
External References
Related Security Bulletins
- Remote code execution in H2 database
- Ubuntu update for h2database
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Console
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- Debian update for h2database
- Multiple vulnerabilities in Oracle Healthcare Translational Research
- Multiple vulnerabilities in Oracle SOA Suite
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7