Code Injection in Apache Commons Configuration - CVE-2022-33980

 

Code Injection in Apache Commons Configuration - CVE-2022-33980

Published: July 6, 2022 / Updated: October 19, 2022


Vulnerability identifier: #VU64957
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33980
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Apache Commons Configuration
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
IBM Sterling Connect:Direct for Microsoft Windows
Oracle Business Intelligence Enterprise Edition
Oracle Retail Xstore Point of Service
Db2 Graph
IBM Cloud Pak for Watson AIOps
Debian Linux
IBM Operations Analytics Predictive Insights
Log Analysis
Oracle Banking Enterprise Default Management
Oracle Banking Deposits and Lines of Credit Servicing
Oracle Banking Party Management
IBM SPSS Analytic Server
IBM Common Licensing
Infrastructure Technology
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
IBM SPSS Modeler
Sterling Connect Direct File Agent
IBM Cloud Pak for Multicloud Management Monitoring
IBM Sterling Connect:Direct for UNIX
IBM Sterling Control Center
Red Hat Satellite
IBM Data Risk Manager
Oracle Financial Services Crime and Compliance Management Studio
Pipeline Utility Steps
AMQ Broker
Fuse
Oracle Healthcare Foundation
Oracle Communications BRM - Elastic Charging Engine
commons-configuration2 (Debian package)
Jazz Reporting Service

How to mitigate CVE-2022-33980

Install updates from vendor's website.

Apache Commons Configuration - update to 2.8.0
Log Analysis - update to 1.3.7.2 IF001
IBM Data Risk Manager - update to 2.0.6.15
Pipeline Utility Steps - update to 2.13.1
IBM SPSS Analytic Server - update to 3.4.0.0.1
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 4.8.0.3.49, 6.0.0.4.56, 6.1.0.2.50, 6.2.0.4.13
AMQ Broker - update to 7.10.1
Fuse - update to 7.11.1
Db2 Graph - addressed in versions 1.0.0.1562-amd64, 1.0.0.1562-s390x, 1.0.0.1562-ppcle, 1.0.0.1598-amd64, 1.0.0.1598-s390x, 1.0.0.1598-ppcle
Sterling Connect Direct File Agent - update to 1.4.0.2.027
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 6
commons-configuration2 (Debian package) - update to 2.8.0-1~deb11u1
IBM Cloud Pak for Watson AIOps - update to 3.4.2
IBM Sterling Connect:Direct for UNIX - addressed in versions 4.3.0.1.102, 6.0.0.2.136, 6.1.0.4.62, 6.2.0.4.18
IBM Sterling Control Center - update to 6.2.1.0.8
Red Hat Satellite - update to 6.13
Jazz Reporting Service - update to 7.0.2 iFix021

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins