Path traversal in Enterprise Security API - CVE-2022-23457

 

Path traversal in Enterprise Security API - CVE-2022-23457

Published: May 20, 2022


Vulnerability identifier: #VU63479
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23457
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in getValidDirectoryPath. A remote attacker can send a specially crafted HTTP request and allow control-flow bypass checks to be defeated.


Affected software

Enterprise Security API
Cloud Pak for Security (CP4S)
IBM Data Risk Manager
Dell Secure Connect Gateway
Oracle Health Sciences Empirica Signal
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Oracle Financial Services Analytical Applications Infrastructure
Oracle WebLogic Server
Oracle GoldenGate Studio
Ubuntu
Primavera Unifier
Cloud Foundry UAA
Bosh Release for the UAA
libowasp-esapi-java (Ubuntu package)

How to mitigate CVE-2022-23457

Install update from vendor's website.

Enterprise Security API - update to 2.3.0.0
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Data Risk Manager - update to 2.0.6.15
Dell Secure Connect Gateway - update to 5.14.00.10
Cloud Foundry UAA - update to 75.20.0
Bosh Release for the UAA - update to 75.20.0
libowasp-esapi-java (Ubuntu package) - addressed in versions 2.1.0-2ubuntu0.1~esm1, 2.1.0-3ubuntu0.18.04.1~esm1, 2.1.0-3ubuntu0.20.04.1~esm1, 2.2.3.1-1ubuntu0.1~esm1, 2.4.0.0-2ubuntu0.1

External References

Related Security Bulletins