Incorrect Regular Expression in Apache Tika - CVE-2022-33879

 

Incorrect Regular Expression in Apache Tika - CVE-2022-33879

Published: June 28, 2022


Vulnerability identifier: #VU64724
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33879
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack.

The vulnerability exists due to improper validation in the StandardsExtractingContentHandler. A remote attacker can pass specially crafted file to the application and perform a denial of service (DoS) attack.

The vulnerability exists due to incomplete fixes for #VU63404 (CVE-2022-30126) and #VU63904 (CVE-2022-30973).


Affected software

Apache Tika
IBM Cloud Transformation Advisor
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Log Analysis
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
Ubuntu
Oracle Healthcare Foundation
Oracle Commerce Guided Search
Oracle Banking Corporate Lending Process Management
Oracle Banking Trade Finance Process Management
Oracle Banking Liquidity Management
Oracle Banking Branch
Oracle Banking Supply Chain Finance
Oracle Banking Cash Management
Oracle Banking Credit Facilities Process Management
Primavera Unifier
Oracle Banking Digital Experience
tika (Ubuntu package)
tika-core

How to mitigate CVE-2022-33879

Install updates from vendor's website.

Apache Tika - addressed in versions 1.28.4, 2.4.1
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Cloud Transformation Advisor - update to 3.2.1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
Oracle Banking Corporate Lending Process Management - update to 14.7.0.0.0
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001
tika (Ubuntu package) - addressed in versions 1.22-1ubuntu0.1~esm1, 1.22-2ubuntu0.22.04.1~esm1
tika-core - addressed in versions 1.26-150200.3.8.1, 1.26-150300.4.3.1

External References

Related Security Bulletins