Input validation error in Apache Tika - CVE-2022-30973
Published: June 1, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the "StandardsText" class in the StandardsExtractingContentHandler. A remote attacker can trick a victim to open a specially crafted file and perform a denial of service (DoS) attack.
Affected software
Red Hat Integration Camel-K
IBM Cloud Transformation Advisor
Log Analysis
IBM Cloud Pak for Business Automation
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
Ubuntu
IBM Qradar SIEM
tika (Ubuntu package)
tika-core
IBM FileNet Content Manager
How to mitigate CVE-2022-30973
Red Hat Integration Camel-K - update to 1.8.1
IBM Cloud Transformation Advisor - update to 3.2.1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001
tika (Ubuntu package) - addressed in versions 1.22-1ubuntu0.1~esm1, 1.22-2ubuntu0.22.04.1~esm1
tika-core - addressed in versions 1.26-150200.3.8.1, 1.26-150300.4.3.1
IBM FileNet Content Manager - addressed in versions 5.5.8.0 IF002, 5.5.9.0 IF001
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
External References
Related Security Bulletins
- Denial of service in Apache Tika
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- SUSE update for tika-core
- SUSE update for tika-core
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat Integration Camel-K
- Denial of service in IBM FileNet Content Manager and IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Ubuntu update for tika