Path traversal in Enterprise Security API - CVE-2022-23457
Published: May 20, 2022
Vulnerability identifier: #VU63479
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-23457
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Affected software:
Enterprise Security API
Cloud Pak for Security (CP4S)
IBM Data Risk Manager
Dell Secure Connect Gateway
Oracle Health Sciences Empirica Signal
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Oracle Financial Services Analytical Applications Infrastructure
Oracle WebLogic Server
Oracle GoldenGate Studio
Ubuntu
Primavera Unifier
Cloud Foundry UAA
Bosh Release for the UAA
libowasp-esapi-java (Ubuntu package)
Enterprise Security API
Cloud Pak for Security (CP4S)
IBM Data Risk Manager
Dell Secure Connect Gateway
Oracle Health Sciences Empirica Signal
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Oracle Financial Services Analytical Applications Infrastructure
Oracle WebLogic Server
Oracle GoldenGate Studio
Ubuntu
Primavera Unifier
Cloud Foundry UAA
Bosh Release for the UAA
libowasp-esapi-java (Ubuntu package)
Detailed vulnerability description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in getValidDirectoryPath. A remote attacker can send a specially crafted HTTP request and allow control-flow bypass checks to be defeated.
How to mitigate CVE-2022-23457
Install update from vendor's website.