Input validation error in Spring Framework - CVE-2022-22970

 

Input validation error in Spring Framework - CVE-2022-22970

Published: May 12, 2022


Vulnerability identifier: #VU63084
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22970
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input within the Spring MVC or Spring WebFlux applications. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Spring Framework
IBM i Modernization Engine for Lifecycle Integration
Dell Policy Manager for Secure Connect Gateway (SCG)
Terracotta
Storage Copy Data Management
IBM OpenPages with Watson
IBM Engineering Requirements Management DOORS Next
Storage Protect Plus Server
Oracle Communications Cloud Native Core Policy
watsonx.data
IBM Watson Discovery for IBM Cloud Pak for Data
Dell Secure Connect Gateway
IBM Sterling Partner Engagement Manager
IBM Rational Build Forge
IBM SPSS Collaboration and Deployment Services
IBM Common Licensing
Autodesk Infraworks
Netcool Operations Insight
IBM Sterling B2B Integrator
Unified Data Protection
IBM Qradar SIEM
AMQ Broker
Zimbra Collaboration
IBM Watson Explorer Foundational Components Annotation Administration Console
IBM Watson Explorer Foundational Components
IBM Watson Explorer Analytical Components
Watson Explorer Deep Analytics Edition Foundational Components Annotation Administration Console
IBM Watson Explorer Deep Analytics Edition Foundational Components
IBM Watson Explorer Deep Analytics Edition Analytical Components
Library Support for Spring

How to mitigate CVE-2022-22970

Install updates from vendor's website.

Spring Framework - addressed in versions 5.2.22, 5.3.20
IBM i Modernization Engine for Lifecycle Integration - update to 1.0.1
watsonx.data - update to 2.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.5.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.12.00.00
Dell Secure Connect Gateway - update to 5.16
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.6, 6.2.0.4, 6.2.1.1
Unified Data Protection - update to 9.1
AMQ Broker - addressed in versions 7.10.3, 7.11.0
IBM Rational Build Forge - update to 8.0.0.29
Zimbra Collaboration - addressed in versions 8.8.15 Patch 40, 9.0.0 Patch 33, 10.0.1
IBM Watson Explorer Foundational Components Annotation Administration Console - update to 11.0.2.14
IBM Watson Explorer Foundational Components - update to 11.0.2.14
IBM Watson Explorer Analytical Components - update to 11.0.2.14
Terracotta - update to 11.1.0
Watson Explorer Deep Analytics Edition Foundational Components Annotation Administration Console - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.10
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Netcool Operations Insight - update to 1.6.8
Storage Copy Data Management - update to 2.2.23.0
Library Support for Spring - update to 2.7.29
IBM Sterling B2B Integrator - addressed in versions 6.0.3.8, 6.1.0.6, 6.1.1.3, 6.1.2.1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
IBM OpenPages with Watson - addressed in versions 8.2.0.4.7, 8.2.0.5, 8.3.0.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
Storage Protect Plus Server - update to 10.1.16.1

External References

Related Security Bulletins