Improper input validation in Oracle WebLogic Server - CVE-2022-24839

 

Improper input validation in Oracle WebLogic Server - CVE-2022-24839

Published: July 20, 2022 / Updated: March 26, 2024


Vulnerability identifier: #VU65486
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24839
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Centralized Third Party Jars (NekoHTML) component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to perform a denial of service (DoS) attack.


Affected software

Oracle WebLogic Server
Bitbucket Server
Log Analysis
IBM Cloud Transformation Advisor
Oracle StorageTek Tape Analytics (STA)
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Server
Jira Service Management Data Center
IBM Sterling Control Center
Confluence Data Center
IBM Tivoli Netcool Impact
IBM TXSeries for Multiplatforms
Jira Software Data Center
Bamboo Server
IBM Security Verify Governance
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Netcool Operations Insight
IBM Sterling Secure Proxy
Bitbucket Data Center
HPE Telco IP Mediation E-Media
Maximo Manage Application in IBM Maximo Application Suite
IBM Robotic Process Automation
IBM Watson Machine Learning Accelerator
PowerVM NovaLink
Oracle Solaris Cluster
IBM i
openEuler
Crowd Server
Confluence Server
Jira Software Server
Oracle FLEXCUBE Core Banking
IBM Qradar SIEM
Oracle Agile PLM Framework
IBM CICS TX Advanced
IBM CICS TX Standard
nekohtml
Liberty for Java for IBM Cloud

How to mitigate CVE-2022-24839

Install updates from vendor's website.

Log Analysis - update to 1.3.8.1
IBM Cloud Transformation Advisor - update to 3.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.0
Jira Service Management Server - addressed in versions 4.20.28, 5.4.12
Jira Service Management Data Center - addressed in versions 4.20.28, 5.4.12
Crowd Server - addressed in versions 5.0.8, 5.1.6, 5.2.1
IBM Sterling Control Center - update to 6.1.3.0.14
Confluence Data Center - addressed in versions 7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.1, 8.6.2, 8.7.1
Confluence Server - addressed in versions 7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.1, 8.6.2
IBM Tivoli Netcool Impact - update to 7.1.0.28
Jira Software Server - addressed in versions 9.4.18, 9.12.5, 9.14.0
Jira Software Data Center - addressed in versions 9.4.18, 9.12.5, 9.14.0
Bamboo Server - addressed in versions 9.2.7, 9.3.5
IBM Security Verify Governance - update to 10.0.1.0.3
Netcool Operations Insight - update to 1.6.6
nekohtml - update to 1.9.22-9
PowerVM NovaLink - addressed in versions 2.0.1-220923, 2.0.3.1.1-220923
Liberty for Java for IBM Cloud - update to 3.75-20221012-1015
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
Bitbucket Server - addressed in versions 7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2
Bitbucket Data Center - addressed in versions 7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2
HPE Telco IP Mediation E-Media - update to 8.5.1
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.5.6, 8.6.2
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix12, 11.1.0.0 ifix5
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM Robotic Process Automation - update to 21.0.7

External References

Related Security Bulletins