Security features bypass in Spring Framework - CVE-2022-22968

 

Security features bypass in Spring Framework - CVE-2022-22968

Published: April 14, 2022 / Updated: May 12, 2022


Vulnerability identifier: #VU62314
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22968
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to patterns for disallowedFields on a DataBinder are case sensitive, which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path. A remote attacker can bypass implemented security restrictions by passing case sensitive data to the application.


Affected software

Spring Framework
IBM i Modernization Engine for Lifecycle Integration
DB2 Data Management Console
OpenPages for IBM Cloud Pak for Data
DevOps Solution Workbench
Dell Policy Manager for Secure Connect Gateway (SCG)
IBM Tivoli Netcool Configuration Manager
OpenPages Cloud pak for data service version
IBM Engineering Requirements Management DOORS Next
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Cloudera Observability with IBM
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
IBM OpenPages with Watson
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Symphony
IBM SPSS Collaboration and Deployment Services
IBM Rational Build Forge
IBM Common Licensing
Autodesk Infraworks
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
watsonx.data
IBM Db2 Web Query for i
AMQ Broker
Oracle WebLogic Server
IBM Qradar SIEM
IBM Cognos Controller
MySQL Enterprise Monitor
IBM Watson Explorer Foundational Components Annotation Administration Console
IBM Watson Explorer Foundational Components
IBM Watson Explorer Analytical Components
IBM Watson Explorer Deep Analytics Edition Analytical Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
Watson Explorer Deep Analytics Edition Foundational Components Annotation Administration Console
Cloud Foundry UAA
Library Support for Spring
Operational Decision Manager

How to mitigate CVE-2022-22968

Install updates from vendor's website.

Spring Framework - addressed in versions 5.2.21, 5.3.19
IBM i Modernization Engine for Lifecycle Integration - update to 1.0.1
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.1.3
DB2 Data Management Console - update to 3.1.13.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.5.0
OpenPages for IBM Cloud Pak for Data - update to 5.2.2
DevOps Solution Workbench - update to 5.1
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.12.00.00
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.22
AMQ Broker - update to 7.10.0
IBM Spectrum Symphony - update to 7.3.2 FP3
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
MySQL Enterprise Monitor - update to 8.0.30
IBM Rational Build Forge - update to 8.0.0.29
OpenPages Cloud pak for data service version - update to 9.5.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
IBM Watson Explorer Foundational Components Annotation Administration Console - update to 11.0.2.14
IBM Watson Explorer Foundational Components - update to 11.0.2.14
IBM Watson Explorer Analytical Components - update to 11.0.2.14
IBM Cognos Controller - update to 11.1.2
IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.10
Watson Explorer Deep Analytics Edition Foundational Components Annotation Administration Console - update to 12.0.3.10
Cloud Foundry UAA - update to 75.19.0
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Library Support for Spring - update to 2.7.29
Cloudera Observability with IBM - update to 3.6.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.5.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1
IBM OpenPages with Watson - addressed in versions 8.2.0.4.7, 8.2.0.5, 8.3.0.2
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 49, 8.11.1 Interim fix 47, 8.12.0.1 Interim fix 31, 9.0.0.1 Interim fix 15, 9.5.0.0 Interim fix 7
IBM Business Automation Workflow - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins