Input validation error in Spring Framework - CVE-2022-22971

 

Input validation error in Spring Framework - CVE-2022-22971

Published: May 12, 2022 / Updated: November 28, 2022


Vulnerability identifier: #VU63085
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22971
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input within the Spring application with a STOMP over WebSocket endpoint. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Spring Framework
IBM Watson Discovery for IBM Cloud Pak for Data
Dell Secure Connect Gateway
IBM Sterling Partner Engagement Manager
Oracle Communications Unified Inventory Management
IBM SPSS Collaboration and Deployment Services
Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition
Oracle Financial Services Behavior Detection Platform
Oracle Financial Services Enterprise Case Management
Oracle Financial Services Model Management and Governance
Oracle Healthcare Data Repository
Oracle Communications Diameter Intelligence Hub
IBM Common Licensing
Oracle SD-WAN Edge
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
IBM Sterling Control Center
Oracle Healthcare Translational Research
Oracle Hospitality Cruise Shipboard Property Management System
Oracle Healthcare Master Person Index
RecoverPoint Classic
Oracle Financial Services Analytical Applications Infrastructure
Oracle Data Integrator
Oracle Retail Customer Insights
Oracle Retail Xstore Point of Service
Storage Copy Data Management
IBM OpenPages with Watson
IBM Engineering Requirements Management DOORS Next
Storage Protect Plus Server
Oracle Utilities Testing Accelerator
Oracle Financial Services Crime and Compliance Management Studio
Oracle Communications Element Manager
Documaker Enterprise Edition
Oracle Banking Corporate Lending Process Management
Siebel Engineering - Installer & Deployment
Oracle Communications Interactive Session Recorder
Unified Data Protection
IBM Qradar SIEM
AMQ Broker
Oracle WebLogic Server
Oracle Retail Predictive Application Server
MySQL Enterprise Monitor
Oracle Communications BRM - Elastic Charging Engine
IBM Watson Explorer Foundational Components
IBM Watson Explorer Analytical Components
IBM Watson Explorer Foundational Components Annotation Administration Console
IBM Watson Explorer Deep Analytics Edition Foundational Components
IBM Watson Explorer Deep Analytics Edition Analytical Components
Watson Explorer Deep Analytics Edition Foundational Components Annotation Administration Console
Oracle Commerce Platform
Oracle Retail Fiscal Management
Oracle Retail Assortment Planning
Oracle Retail Customer Management and Segmentation Foundation
Oracle Retail Merchandising System
Oracle Enterprise Manager for Fusion Middleware
Library Support for Spring
RSA Authentication Manager

How to mitigate CVE-2022-22971

Install updates from vendor's website.

Spring Framework - addressed in versions 5.2.22, 5.3.20
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.5.0
RecoverPoint Classic - update to 5.1 SP4 P4
Dell Secure Connect Gateway - update to 5.16
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.6, 6.2.0.4, 6.2.1.1
Unified Data Protection - update to 9.1
AMQ Broker - addressed in versions 7.10.3, 7.11.0
IBM Watson Explorer Foundational Components - update to 11.0.2.14
IBM Watson Explorer Analytical Components - update to 11.0.2.14
IBM Watson Explorer Foundational Components Annotation Administration Console - update to 11.0.2.14
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.10
Watson Explorer Deep Analytics Edition Foundational Components Annotation Administration Console - update to 12.0.3.10
Netcool Operations Insight - update to 1.6.8
Storage Copy Data Management - update to 2.2.23.0
Library Support for Spring - update to 2.7.29
IBM Sterling Control Center - update to 6.2.1.0.8
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
IBM OpenPages with Watson - addressed in versions 8.2.0.4.7, 8.2.0.5, 8.3.0.2
RSA Authentication Manager - update to 8.7 Patch 2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
Storage Protect Plus Server - update to 10.1.16.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins