Input validation error in Spring Cloud Function - CVE-2022-22979

 

Input validation error in Spring Cloud Function - CVE-2022-22979

Published: June 16, 2022


Vulnerability identifier: #VU64423
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22979
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the caching issue in Function Catalog component of the framework. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack via spring-cloud-function-web module.


Affected software

Spring Cloud Function
Oracle Banking Corporate Lending Process Management
Oracle Banking Origination
Oracle Banking Electronic Data Exchange for Corporates
Oracle Banking Cash Management
Oracle Banking Branch
Oracle Banking Trade Finance Process Management
Oracle Banking Supply Chain Finance
Oracle Banking Credit Facilities Process Management
Oracle Banking Virtual Account Management
Oracle Banking Liquidity Management

How to mitigate CVE-2022-22979

Install updates from vendor's website.

Spring Cloud Function - update to 3.2.6

External References

Related Security Bulletins