Resource management error in Jetty - CVE-2022-2048
Published: July 27, 2022
Vulnerability identifier: #VU65830
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2048
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application when handling invalid HTTP/2 requests. A remote attacker can send specially crafted requests to the server and perform a denial of service (DoS) attack.
Affected software
Jetty
IBM Observability with Instana
IBM Process Mining
IBM Sterling Secure Proxy
Netcool/OMNIbus
Rational Service Tester
Rational Functional Tester (RFT)
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
IBM Spectrum Protect Storage Agent
Jenkins
Jenkins LTS
Fuse
AMQ Streams
Red Hat OpenShift Container Platform
Oracle Autovue for Agile Product Lifecycle Management
IBM Tivoli Network Manager (ITNM)
Rational Change
Oracle Financial Services Crime and Compliance Management Studio
Oracle Communications Element Manager
Oracle Banking Corporate Lending Process Management
Oracle Banking Cash Management
Oracle Banking Supply Chain Finance
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
IBM Cognos Command Center
Rational Performance Tester
Installation Manager
Packaging Utility
IBM Cloud Pak for Watson AIOps
User Entity Behavior Analytics
Oracle Retail EFTLink
openEuler
Anolis OS
Oracle AutoVue
Operational Decision Manager
Oracle Communications Cloud Native Core Policy
watsonx.data
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
jetty-alpn-client
jetty-osgi-alpn
jetty-jsp
jetty-quickstart
jetty-http2-common
jetty-ant
jetty-servlets
jetty-cdi
jetty-util-ajax
jetty-jstl
jetty-infinispan
jetty-http
jetty-security
jetty-jndi
jetty-jaas
jetty-rewrite
jetty-http-spi
jetty-jspc-maven-plugin
jetty-start
jetty-http2-hpack
jetty-websocket-client
jetty-jmx
jetty-fcgi-client
jetty-http2-client
jetty-osgi-boot-jsp
jetty-websocket-servlet
jetty-util
jetty-javax-websocket-client-impl
jetty
jetty-plus
jetty-javadoc
jetty-proxy
jetty-xml
jetty-httpservice
jetty-osgi-boot
jetty-client
jetty-spring
jetty-maven-plugin
jetty-project
jetty-continuation
jetty-nosql
jetty-http2-http-client-transport
jetty-javax-websocket-server-impl
jetty-fcgi-server
jetty-osgi-boot-warurl
jetty-websocket-server
jetty-io
jetty-server
jetty-unixsocket
jetty-websocket-api
jetty-jaspi
jetty-websocket-common
jetty-servlet
jetty-annotations
jetty-deploy
jetty-http2-server
jetty-webapp
jetty-alpn-server
jetty9 (Debian package)
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
Communications Unified Assurance
IBM InfoSphere Information Server
IBM Observability with Instana
IBM Process Mining
IBM Sterling Secure Proxy
Netcool/OMNIbus
Rational Service Tester
Rational Functional Tester (RFT)
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
IBM Spectrum Protect Storage Agent
Jenkins
Jenkins LTS
Fuse
AMQ Streams
Red Hat OpenShift Container Platform
Oracle Autovue for Agile Product Lifecycle Management
IBM Tivoli Network Manager (ITNM)
Rational Change
Oracle Financial Services Crime and Compliance Management Studio
Oracle Communications Element Manager
Oracle Banking Corporate Lending Process Management
Oracle Banking Cash Management
Oracle Banking Supply Chain Finance
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
IBM Cognos Command Center
Rational Performance Tester
Installation Manager
Packaging Utility
IBM Cloud Pak for Watson AIOps
User Entity Behavior Analytics
Oracle Retail EFTLink
openEuler
Anolis OS
Oracle AutoVue
Operational Decision Manager
Oracle Communications Cloud Native Core Policy
watsonx.data
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
jetty-alpn-client
jetty-osgi-alpn
jetty-jsp
jetty-quickstart
jetty-http2-common
jetty-ant
jetty-servlets
jetty-cdi
jetty-util-ajax
jetty-jstl
jetty-infinispan
jetty-http
jetty-security
jetty-jndi
jetty-jaas
jetty-rewrite
jetty-http-spi
jetty-jspc-maven-plugin
jetty-start
jetty-http2-hpack
jetty-websocket-client
jetty-jmx
jetty-fcgi-client
jetty-http2-client
jetty-osgi-boot-jsp
jetty-websocket-servlet
jetty-util
jetty-javax-websocket-client-impl
jetty
jetty-plus
jetty-javadoc
jetty-proxy
jetty-xml
jetty-httpservice
jetty-osgi-boot
jetty-client
jetty-spring
jetty-maven-plugin
jetty-project
jetty-continuation
jetty-nosql
jetty-http2-http-client-transport
jetty-javax-websocket-server-impl
jetty-fcgi-server
jetty-osgi-boot-warurl
jetty-websocket-server
jetty-io
jetty-server
jetty-unixsocket
jetty-websocket-api
jetty-jaspi
jetty-websocket-common
jetty-servlet
jetty-annotations
jetty-deploy
jetty-http2-server
jetty-webapp
jetty-alpn-server
jetty9 (Debian package)
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
Communications Unified Assurance
IBM InfoSphere Information Server
How to mitigate CVE-2022-2048
Install updates from vendor's website.
Jetty - addressed in versions 9.4.47.v20220610, 10.0.10, 11.0.10
IBM Process Mining - update to 1.13.0.0
Jenkins - update to 2.363
Jenkins LTS - update to 2.361.1
Red Hat OpenShift Container Platform - addressed in versions 4.8.56, 4.9.56
Rational Change - update to 5.3.2.5
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
Fuse - update to 7.11.1
Netcool/OMNIbus - update to 8.1.0.30
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.17, 22.0.2.1
Netcool Operations Insight - update to 1.6.10
Installation Manager - update to 1.10.1.1
Packaging Utility - update to 1.10.1.1
Cloud Pak for Security (CP4S) - update to 1.10.14.0
watsonx.data - update to 2.0.2
AMQ Streams - update to 2.3.0
jenkins (Red Hat package) - addressed in versions 2.361.1.1672840472-1.el8, 2.361.1.1675668150-1.el8, 2.401.1.1686831596-3.el8
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
jenkins-2-plugins (Red Hat package) - addressed in versions 4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.11.1686831822-1.el8
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
User Entity Behavior Analytics - update to 5.0.2
Communications Unified Assurance - update to 5.5.7
IBM Spectrum Protect Storage Agent - update to 8.1.19
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 39, 8.11.0.1 Interim fix 21, 8.11.1 Interim fix 9, 8.12.0 Interim fix 1
jetty-alpn-client - update to 9.4.16-3
jetty-osgi-alpn - update to 9.4.16-3
jetty-jsp - update to 9.4.16-3
jetty-quickstart - update to 9.4.16-3
jetty-http2-common - update to 9.4.16-3
jetty-ant - update to 9.4.16-3
jetty-servlets - update to 9.4.16-3
jetty-cdi - update to 9.4.16-3
jetty-util-ajax - update to 9.4.16-3
jetty-jstl - update to 9.4.16-3
jetty-infinispan - update to 9.4.16-3
jetty-http - update to 9.4.16-3
jetty-security - update to 9.4.16-3
jetty-jndi - update to 9.4.16-3
jetty-jaas - update to 9.4.16-3
jetty-rewrite - update to 9.4.16-3
jetty-http-spi - update to 9.4.16-3
jetty-jspc-maven-plugin - update to 9.4.16-3
jetty-start - update to 9.4.16-3
jetty-http2-hpack - update to 9.4.16-3
jetty-websocket-client - update to 9.4.16-3
jetty-jmx - update to 9.4.16-3
jetty-fcgi-client - update to 9.4.16-3
jetty-http2-client - update to 9.4.16-3
jetty-osgi-boot-jsp - update to 9.4.16-3
jetty-websocket-servlet - update to 9.4.16-3
jetty-util - update to 9.4.16-3
jetty-javax-websocket-client-impl - update to 9.4.16-3
jetty - update to 9.4.16-3
jetty-plus - update to 9.4.16-3
jetty-javadoc - update to 9.4.16-3
jetty-proxy - update to 9.4.16-3
jetty-xml - update to 9.4.16-3
jetty-httpservice - update to 9.4.16-3
jetty-osgi-boot - update to 9.4.16-3
jetty-client - update to 9.4.16-3
jetty-spring - update to 9.4.16-3
jetty-maven-plugin - update to 9.4.16-3
jetty-project - update to 9.4.16-3
jetty-continuation - update to 9.4.16-3
jetty-nosql - update to 9.4.16-3
jetty-http2-http-client-transport - update to 9.4.16-3
jetty-javax-websocket-server-impl - update to 9.4.16-3
jetty-fcgi-server - update to 9.4.16-3
jetty-osgi-boot-warurl - update to 9.4.16-3
jetty-websocket-server - update to 9.4.16-3
jetty-io - update to 9.4.16-3
jetty-server - update to 9.4.16-3
jetty-unixsocket - update to 9.4.16-3
jetty-websocket-api - update to 9.4.16-3
jetty-jaspi - update to 9.4.16-3
jetty-websocket-common - update to 9.4.16-3
jetty-servlet - update to 9.4.16-3
jetty-annotations - update to 9.4.16-3
jetty-deploy - update to 9.4.16-3
jetty-http2-server - update to 9.4.16-3
jetty-webapp - update to 9.4.16-3
jetty-alpn-server - update to 9.4.16-3
jetty9 (Debian package) - update to 9.4.39-3+deb11u1
jetty-jaas - update to 9.4.43-4
jetty-webapp - update to 9.4.43-4
jetty-util-ajax - update to 9.4.43-4
jetty-util - update to 9.4.43-4
jetty-servlet - update to 9.4.43-4
jetty-server - update to 9.4.43-4
jetty-security - update to 9.4.43-4
jetty-jmx - update to 9.4.43-4
jetty-javadoc - update to 9.4.43-4
jetty-io - update to 9.4.43-4
jetty-http - update to 9.4.43-4
jetty-continuation - update to 9.4.43-4
jetty-client - update to 9.4.43-4
jetty - update to 9.4.43-4
jetty-xml - update to 9.4.43-4
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM Process Mining - update to 1.13.0.0
Jenkins - update to 2.363
Jenkins LTS - update to 2.361.1
Red Hat OpenShift Container Platform - addressed in versions 4.8.56, 4.9.56
Rational Change - update to 5.3.2.5
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
Fuse - update to 7.11.1
Netcool/OMNIbus - update to 8.1.0.30
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.17, 22.0.2.1
Netcool Operations Insight - update to 1.6.10
Installation Manager - update to 1.10.1.1
Packaging Utility - update to 1.10.1.1
Cloud Pak for Security (CP4S) - update to 1.10.14.0
watsonx.data - update to 2.0.2
AMQ Streams - update to 2.3.0
jenkins (Red Hat package) - addressed in versions 2.361.1.1672840472-1.el8, 2.361.1.1675668150-1.el8, 2.401.1.1686831596-3.el8
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
jenkins-2-plugins (Red Hat package) - addressed in versions 4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.11.1686831822-1.el8
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
User Entity Behavior Analytics - update to 5.0.2
Communications Unified Assurance - update to 5.5.7
IBM Spectrum Protect Storage Agent - update to 8.1.19
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 39, 8.11.0.1 Interim fix 21, 8.11.1 Interim fix 9, 8.12.0 Interim fix 1
jetty-alpn-client - update to 9.4.16-3
jetty-osgi-alpn - update to 9.4.16-3
jetty-jsp - update to 9.4.16-3
jetty-quickstart - update to 9.4.16-3
jetty-http2-common - update to 9.4.16-3
jetty-ant - update to 9.4.16-3
jetty-servlets - update to 9.4.16-3
jetty-cdi - update to 9.4.16-3
jetty-util-ajax - update to 9.4.16-3
jetty-jstl - update to 9.4.16-3
jetty-infinispan - update to 9.4.16-3
jetty-http - update to 9.4.16-3
jetty-security - update to 9.4.16-3
jetty-jndi - update to 9.4.16-3
jetty-jaas - update to 9.4.16-3
jetty-rewrite - update to 9.4.16-3
jetty-http-spi - update to 9.4.16-3
jetty-jspc-maven-plugin - update to 9.4.16-3
jetty-start - update to 9.4.16-3
jetty-http2-hpack - update to 9.4.16-3
jetty-websocket-client - update to 9.4.16-3
jetty-jmx - update to 9.4.16-3
jetty-fcgi-client - update to 9.4.16-3
jetty-http2-client - update to 9.4.16-3
jetty-osgi-boot-jsp - update to 9.4.16-3
jetty-websocket-servlet - update to 9.4.16-3
jetty-util - update to 9.4.16-3
jetty-javax-websocket-client-impl - update to 9.4.16-3
jetty - update to 9.4.16-3
jetty-plus - update to 9.4.16-3
jetty-javadoc - update to 9.4.16-3
jetty-proxy - update to 9.4.16-3
jetty-xml - update to 9.4.16-3
jetty-httpservice - update to 9.4.16-3
jetty-osgi-boot - update to 9.4.16-3
jetty-client - update to 9.4.16-3
jetty-spring - update to 9.4.16-3
jetty-maven-plugin - update to 9.4.16-3
jetty-project - update to 9.4.16-3
jetty-continuation - update to 9.4.16-3
jetty-nosql - update to 9.4.16-3
jetty-http2-http-client-transport - update to 9.4.16-3
jetty-javax-websocket-server-impl - update to 9.4.16-3
jetty-fcgi-server - update to 9.4.16-3
jetty-osgi-boot-warurl - update to 9.4.16-3
jetty-websocket-server - update to 9.4.16-3
jetty-io - update to 9.4.16-3
jetty-server - update to 9.4.16-3
jetty-unixsocket - update to 9.4.16-3
jetty-websocket-api - update to 9.4.16-3
jetty-jaspi - update to 9.4.16-3
jetty-websocket-common - update to 9.4.16-3
jetty-servlet - update to 9.4.16-3
jetty-annotations - update to 9.4.16-3
jetty-deploy - update to 9.4.16-3
jetty-http2-server - update to 9.4.16-3
jetty-webapp - update to 9.4.16-3
jetty-alpn-server - update to 9.4.16-3
jetty9 (Debian package) - update to 9.4.39-3+deb11u1
jetty-jaas - update to 9.4.43-4
jetty-webapp - update to 9.4.43-4
jetty-util-ajax - update to 9.4.43-4
jetty-util - update to 9.4.43-4
jetty-servlet - update to 9.4.43-4
jetty-server - update to 9.4.43-4
jetty-security - update to 9.4.43-4
jetty-jmx - update to 9.4.43-4
jetty-javadoc - update to 9.4.43-4
jetty-io - update to 9.4.43-4
jetty-http - update to 9.4.43-4
jetty-continuation - update to 9.4.43-4
jetty-client - update to 9.4.43-4
jetty - update to 9.4.43-4
jetty-xml - update to 9.4.43-4
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
External References
Related Security Bulletins
- Multiple vulnerabilities in Eclipse Jetty
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- Debian update for jetty9
- IBM Process Mining update for Eclipse Jetty
- IBM Rational Functional Tester update for Eclipse Jetty
- Denial of service in Jenkins
- Multiple vulnerabilities in IBM Rational Change
- Multiple vulnerabilities in Oracle Communications Element Manager
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Oracle Autovue for Agile Product Lifecycle Management
- Multiple vulnerabilities in Oracle AutoVue
- Multiple vulnerabilities in Oracle Retail EFTLink
- Multiple vulnerabilities in IBM QRadar SIEM
- IBM Rational Service Tester update for Eclipse Jetty
- Multiple vulnerabilities in Red Hat Fuse
- Tivoli Netcool/Omnibus update for Eclipse Jetty
- Multiple vulnerabilities in IBM Tivoli Network Manager
- Multiple vulnerabilities in OpenShift Container Platform 4.8
- Multiple vulnerabilities in Red Hat AMQ Streams
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle Financial Services Crime and Compliance Management Studio
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in Oracle Banking Corporate Lending Process Management
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM InfoSphere Information Server
- OpenShift Developer Tools and Services for OCP 4.11 update for jenkins and jenkins-2-plugins
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Rational Performance Tester
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- openEuler 22.03 LTS SP1 update for jetty
- openEuler 20.03 LTS SP1 update for jetty
- openEuler 20.03 LTS SP3 update for jetty
- openEuler 22.03 LTS update for jetty
- Resource management error in IBM watsonx.data
- Multiple vulnerabilities in IBM Installation Manager and IBM Packaging Utility
- Anolis OS update for jetty
- Multiple vulnerabilities in IBM User Entity Behavior Analytics
- Multiple vulnerabilities in Oracle Banking Supply Chain Finance
- Multiple vulnerabilities in Oracle Banking Cash Management