Resource management error in Jetty - CVE-2022-2048

 

Resource management error in Jetty - CVE-2022-2048

Published: July 27, 2022


Vulnerability identifier: #VU65830
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2048
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application when handling invalid HTTP/2 requests. A remote attacker can send specially crafted requests to the server and perform a denial of service (DoS) attack.


Affected software

Jetty
IBM Observability with Instana
IBM Process Mining
IBM Sterling Secure Proxy
Netcool/OMNIbus
Rational Service Tester
Rational Functional Tester (RFT)
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
IBM Spectrum Protect Storage Agent
Jenkins
Jenkins LTS
Fuse
AMQ Streams
Red Hat OpenShift Container Platform
Oracle Autovue for Agile Product Lifecycle Management
IBM Tivoli Network Manager (ITNM)
Rational Change
Oracle Financial Services Crime and Compliance Management Studio
Oracle Communications Element Manager
Oracle Banking Corporate Lending Process Management
Oracle Banking Cash Management
Oracle Banking Supply Chain Finance
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
IBM Cognos Command Center
Rational Performance Tester
Installation Manager
Packaging Utility
IBM Cloud Pak for Watson AIOps
User Entity Behavior Analytics
Oracle Retail EFTLink
openEuler
Anolis OS
Oracle AutoVue
Operational Decision Manager
Oracle Communications Cloud Native Core Policy
watsonx.data
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
jetty-alpn-client
jetty-osgi-alpn
jetty-jsp
jetty-quickstart
jetty-http2-common
jetty-ant
jetty-servlets
jetty-cdi
jetty-util-ajax
jetty-jstl
jetty-infinispan
jetty-http
jetty-security
jetty-jndi
jetty-jaas
jetty-rewrite
jetty-http-spi
jetty-jspc-maven-plugin
jetty-start
jetty-http2-hpack
jetty-websocket-client
jetty-jmx
jetty-fcgi-client
jetty-http2-client
jetty-osgi-boot-jsp
jetty-websocket-servlet
jetty-util
jetty-javax-websocket-client-impl
jetty
jetty-plus
jetty-javadoc
jetty-proxy
jetty-xml
jetty-httpservice
jetty-osgi-boot
jetty-client
jetty-spring
jetty-maven-plugin
jetty-project
jetty-continuation
jetty-nosql
jetty-http2-http-client-transport
jetty-javax-websocket-server-impl
jetty-fcgi-server
jetty-osgi-boot-warurl
jetty-websocket-server
jetty-io
jetty-server
jetty-unixsocket
jetty-websocket-api
jetty-jaspi
jetty-websocket-common
jetty-servlet
jetty-annotations
jetty-deploy
jetty-http2-server
jetty-webapp
jetty-alpn-server
jetty9 (Debian package)
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
Communications Unified Assurance
IBM InfoSphere Information Server

How to mitigate CVE-2022-2048

Install updates from vendor's website.

Jetty - addressed in versions 9.4.47.v20220610, 10.0.10, 11.0.10
IBM Process Mining - update to 1.13.0.0
Jenkins - update to 2.363
Jenkins LTS - update to 2.361.1
Red Hat OpenShift Container Platform - addressed in versions 4.8.56, 4.9.56
Rational Change - update to 5.3.2.5
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
Fuse - update to 7.11.1
Netcool/OMNIbus - update to 8.1.0.30
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.17, 22.0.2.1
Netcool Operations Insight - update to 1.6.10
Installation Manager - update to 1.10.1.1
Packaging Utility - update to 1.10.1.1
Cloud Pak for Security (CP4S) - update to 1.10.14.0
watsonx.data - update to 2.0.2
AMQ Streams - update to 2.3.0
jenkins (Red Hat package) - addressed in versions 2.361.1.1672840472-1.el8, 2.361.1.1675668150-1.el8, 2.401.1.1686831596-3.el8
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
jenkins-2-plugins (Red Hat package) - addressed in versions 4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.11.1686831822-1.el8
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
User Entity Behavior Analytics - update to 5.0.2
Communications Unified Assurance - update to 5.5.7
IBM Spectrum Protect Storage Agent - update to 8.1.19
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 39, 8.11.0.1 Interim fix 21, 8.11.1 Interim fix 9, 8.12.0 Interim fix 1
jetty-alpn-client - update to 9.4.16-3
jetty-osgi-alpn - update to 9.4.16-3
jetty-jsp - update to 9.4.16-3
jetty-quickstart - update to 9.4.16-3
jetty-http2-common - update to 9.4.16-3
jetty-ant - update to 9.4.16-3
jetty-servlets - update to 9.4.16-3
jetty-cdi - update to 9.4.16-3
jetty-util-ajax - update to 9.4.16-3
jetty-jstl - update to 9.4.16-3
jetty-infinispan - update to 9.4.16-3
jetty-http - update to 9.4.16-3
jetty-security - update to 9.4.16-3
jetty-jndi - update to 9.4.16-3
jetty-jaas - update to 9.4.16-3
jetty-rewrite - update to 9.4.16-3
jetty-http-spi - update to 9.4.16-3
jetty-jspc-maven-plugin - update to 9.4.16-3
jetty-start - update to 9.4.16-3
jetty-http2-hpack - update to 9.4.16-3
jetty-websocket-client - update to 9.4.16-3
jetty-jmx - update to 9.4.16-3
jetty-fcgi-client - update to 9.4.16-3
jetty-http2-client - update to 9.4.16-3
jetty-osgi-boot-jsp - update to 9.4.16-3
jetty-websocket-servlet - update to 9.4.16-3
jetty-util - update to 9.4.16-3
jetty-javax-websocket-client-impl - update to 9.4.16-3
jetty - update to 9.4.16-3
jetty-plus - update to 9.4.16-3
jetty-javadoc - update to 9.4.16-3
jetty-proxy - update to 9.4.16-3
jetty-xml - update to 9.4.16-3
jetty-httpservice - update to 9.4.16-3
jetty-osgi-boot - update to 9.4.16-3
jetty-client - update to 9.4.16-3
jetty-spring - update to 9.4.16-3
jetty-maven-plugin - update to 9.4.16-3
jetty-project - update to 9.4.16-3
jetty-continuation - update to 9.4.16-3
jetty-nosql - update to 9.4.16-3
jetty-http2-http-client-transport - update to 9.4.16-3
jetty-javax-websocket-server-impl - update to 9.4.16-3
jetty-fcgi-server - update to 9.4.16-3
jetty-osgi-boot-warurl - update to 9.4.16-3
jetty-websocket-server - update to 9.4.16-3
jetty-io - update to 9.4.16-3
jetty-server - update to 9.4.16-3
jetty-unixsocket - update to 9.4.16-3
jetty-websocket-api - update to 9.4.16-3
jetty-jaspi - update to 9.4.16-3
jetty-websocket-common - update to 9.4.16-3
jetty-servlet - update to 9.4.16-3
jetty-annotations - update to 9.4.16-3
jetty-deploy - update to 9.4.16-3
jetty-http2-server - update to 9.4.16-3
jetty-webapp - update to 9.4.16-3
jetty-alpn-server - update to 9.4.16-3
jetty9 (Debian package) - update to 9.4.39-3+deb11u1
jetty-jaas - update to 9.4.43-4
jetty-webapp - update to 9.4.43-4
jetty-util-ajax - update to 9.4.43-4
jetty-util - update to 9.4.43-4
jetty-servlet - update to 9.4.43-4
jetty-server - update to 9.4.43-4
jetty-security - update to 9.4.43-4
jetty-jmx - update to 9.4.43-4
jetty-javadoc - update to 9.4.43-4
jetty-io - update to 9.4.43-4
jetty-http - update to 9.4.43-4
jetty-continuation - update to 9.4.43-4
jetty-client - update to 9.4.43-4
jetty - update to 9.4.43-4
jetty-xml - update to 9.4.43-4
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

External References

Related Security Bulletins