Input validation error in Jetty - CVE-2022-2047

 

Input validation error in Jetty - CVE-2022-2047

Published: July 27, 2022


Vulnerability identifier: #VU65831
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2047
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient validation of user-supplied input when parsing invalid URIs such as http://localhost;/path. A remote attacker can pass specially crafted input to the application and bypass implemented security restrictions, as the Jetty's HttpClient, and Jetty's ProxyServlet / AsyncProxyServlet / AsyncMiddleManServlet will wrongly interpret an authority of such URI as the one with a hostname.


Affected software

Jetty
Installation Manager
Cloudera Observability with IBM
Rational Performance Tester
IBM Security Verify Information Queue
IBM Cloud Pak for Watson AIOps
User Entity Behavior Analytics
StreamSets Data Collector
IBM Engineering Systems Design Rhapsody
webMethods BPM
IBM Process Mining
IBM Sterling Secure Proxy
Netcool/OMNIbus
Rational Service Tester
Rational Functional Tester (RFT)
IBM Integration Bus
IBM Cloud Pak for Business Automation
Log Analysis
Netcool Operations Insight
IBM Cloud Pak for Data System
IBM Maximo Asset Management
IBM Maximo Application Suite
IBM Security Verify Governance
IBM Spectrum Protect Plus
Rational Change
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
IBM Cognos Command Center
IBM App Connect Enterprise
openEuler
Anolis OS
AMQ Streams
AMQ Broker
IBM Tivoli Network Manager (ITNM)
Operational Decision Manager
jetty-alpn-client
jetty-fcgi-server
jetty-jsp
jetty-quickstart
jetty-http2-common
jetty-ant
jetty-servlets
jetty-cdi
jetty-util-ajax
jetty-jstl
jetty-infinispan
jetty-http
jetty-security
jetty-jndi
jetty-osgi-alpn
jetty-rewrite
jetty-http-spi
jetty-jspc-maven-plugin
jetty-start
jetty-http2-hpack
jetty-websocket-client
jetty-jmx
jetty-fcgi-client
jetty-http2-client
jetty-osgi-boot-jsp
jetty-websocket-servlet
jetty-jaas
jetty-util
jetty-javax-websocket-client-impl
jetty-maven-plugin
jetty-http2-http-client-transport
jetty-http2-server
jetty
jetty-proxy
jetty-xml
jetty-httpservice
jetty-osgi-boot
jetty-client
jetty-spring
jetty-project
jetty-javadoc
jetty-continuation
jetty-nosql
jetty-webapp
jetty-javax-websocket-server-impl
jetty-plus
jetty-osgi-boot-warurl
jetty-websocket-server
jetty-io
jetty-server
jetty-unixsocket
jetty-websocket-api
jetty-jaspi
jetty-websocket-common
jetty-servlet
jetty-annotations
jetty-deploy
jetty-alpn-server
jetty9 (Debian package)
IBM InfoSphere Information Server

How to mitigate CVE-2022-2047

Install updates from vendor's website.

Jetty - addressed in versions 9.4.47.v20220610, 10.0.10, 11.0.10
Installation Manager - update to 1.10.1.0
IBM Process Mining - update to 1.13.1
Rational Change - update to 5.3.2.5
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
Netcool/OMNIbus - update to 8.1.0.30
IBM Security Verify Information Queue - update to 10.0.5
IBM Integration Bus - update to 10.1.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.16, 22.0.1.6
Log Analysis - addressed in versions 1.3.7.2 IF001, 1.3.7.2 IF002
Netcool Operations Insight - update to 1.6.10
Cloud Pak for Security (CP4S) - update to 1.10.14.0
IBM Cloud Pak for Data System - update to 2.0.2.1
AMQ Streams - update to 2.3.0
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
User Entity Behavior Analytics - update to 5.0.2
StreamSets Data Collector - update to 7.0.0
IBM Maximo Asset Management - update to 7.6.1.3.0.4
AMQ Broker - update to 7.11.0
IBM Maximo Application Suite - addressed in versions 8.4.6, 8.5
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 41, 8.11.0.1 Interim fix 21, 8.11.1 Interim fix 10, 8.12.0 Interim fix 2
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
jetty-alpn-client - update to 9.4.16-3
jetty-fcgi-server - update to 9.4.16-3
jetty-jsp - update to 9.4.16-3
jetty-quickstart - update to 9.4.16-3
jetty-http2-common - update to 9.4.16-3
jetty-ant - update to 9.4.16-3
jetty-servlets - update to 9.4.16-3
jetty-cdi - update to 9.4.16-3
jetty-util-ajax - update to 9.4.16-3
jetty-jstl - update to 9.4.16-3
jetty-infinispan - update to 9.4.16-3
jetty-http - update to 9.4.16-3
jetty-security - update to 9.4.16-3
jetty-jndi - update to 9.4.16-3
jetty-osgi-alpn - update to 9.4.16-3
jetty-rewrite - update to 9.4.16-3
jetty-http-spi - update to 9.4.16-3
jetty-jspc-maven-plugin - update to 9.4.16-3
jetty-start - update to 9.4.16-3
jetty-http2-hpack - update to 9.4.16-3
jetty-websocket-client - update to 9.4.16-3
jetty-jmx - update to 9.4.16-3
jetty-fcgi-client - update to 9.4.16-3
jetty-http2-client - update to 9.4.16-3
jetty-osgi-boot-jsp - update to 9.4.16-3
jetty-websocket-servlet - update to 9.4.16-3
jetty-jaas - update to 9.4.16-3
jetty-util - update to 9.4.16-3
jetty-javax-websocket-client-impl - update to 9.4.16-3
jetty-maven-plugin - update to 9.4.16-3
jetty-http2-http-client-transport - update to 9.4.16-3
jetty-http2-server - update to 9.4.16-3
jetty - update to 9.4.16-3
jetty-proxy - update to 9.4.16-3
jetty-xml - update to 9.4.16-3
jetty-httpservice - update to 9.4.16-3
jetty-osgi-boot - update to 9.4.16-3
jetty-client - update to 9.4.16-3
jetty-spring - update to 9.4.16-3
jetty-project - update to 9.4.16-3
jetty-javadoc - update to 9.4.16-3
jetty-continuation - update to 9.4.16-3
jetty-nosql - update to 9.4.16-3
jetty-webapp - update to 9.4.16-3
jetty-javax-websocket-server-impl - update to 9.4.16-3
jetty-plus - update to 9.4.16-3
jetty-osgi-boot-warurl - update to 9.4.16-3
jetty-websocket-server - update to 9.4.16-3
jetty-io - update to 9.4.16-3
jetty-server - update to 9.4.16-3
jetty-unixsocket - update to 9.4.16-3
jetty-websocket-api - update to 9.4.16-3
jetty-jaspi - update to 9.4.16-3
jetty-websocket-common - update to 9.4.16-3
jetty-servlet - update to 9.4.16-3
jetty-annotations - update to 9.4.16-3
jetty-deploy - update to 9.4.16-3
jetty-alpn-server - update to 9.4.16-3
jetty9 (Debian package) - update to 9.4.39-3+deb11u1
jetty - update to 9.4.43-6
jetty-client - update to 9.4.43-6
jetty-continuation - update to 9.4.43-6
jetty-http - update to 9.4.43-6
jetty-io - update to 9.4.43-6
jetty-jaas - update to 9.4.43-6
jetty-javadoc - update to 9.4.43-6
jetty-jmx - update to 9.4.43-6
jetty-security - update to 9.4.43-6
jetty-server - update to 9.4.43-6
jetty-xml - update to 9.4.43-6
jetty-webapp - update to 9.4.43-6
jetty-util-ajax - update to 9.4.43-6
jetty-util - update to 9.4.43-6
jetty-servlet - update to 9.4.43-6
IBM Security Verify Governance - update to 10.0.1.0.3
IBM Spectrum Protect Plus - update to 10.1.14
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
webMethods BPM - addressed in versions 10.15 Fix 15, 11.1 Fix 3
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

External References

Related Security Bulletins