Input validation error in Jetty - CVE-2022-2047
Published: July 27, 2022
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input when parsing invalid URIs such as http://localhost;/path. A remote attacker can pass specially crafted input to the application and bypass implemented security restrictions, as the Jetty's HttpClient, and Jetty's ProxyServlet / AsyncProxyServlet / AsyncMiddleManServlet will wrongly interpret an authority of such URI as the one with a hostname.
Affected software
Installation Manager
Cloudera Observability with IBM
Rational Performance Tester
IBM Security Verify Information Queue
IBM Cloud Pak for Watson AIOps
User Entity Behavior Analytics
StreamSets Data Collector
IBM Engineering Systems Design Rhapsody
webMethods BPM
IBM Process Mining
IBM Sterling Secure Proxy
Netcool/OMNIbus
Rational Service Tester
Rational Functional Tester (RFT)
IBM Integration Bus
IBM Cloud Pak for Business Automation
Log Analysis
Netcool Operations Insight
IBM Cloud Pak for Data System
IBM Maximo Asset Management
IBM Maximo Application Suite
IBM Security Verify Governance
IBM Spectrum Protect Plus
Rational Change
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
IBM Cognos Command Center
IBM App Connect Enterprise
openEuler
Anolis OS
AMQ Streams
AMQ Broker
IBM Tivoli Network Manager (ITNM)
Operational Decision Manager
jetty-alpn-client
jetty-fcgi-server
jetty-jsp
jetty-quickstart
jetty-http2-common
jetty-ant
jetty-servlets
jetty-cdi
jetty-util-ajax
jetty-jstl
jetty-infinispan
jetty-http
jetty-security
jetty-jndi
jetty-osgi-alpn
jetty-rewrite
jetty-http-spi
jetty-jspc-maven-plugin
jetty-start
jetty-http2-hpack
jetty-websocket-client
jetty-jmx
jetty-fcgi-client
jetty-http2-client
jetty-osgi-boot-jsp
jetty-websocket-servlet
jetty-jaas
jetty-util
jetty-javax-websocket-client-impl
jetty-maven-plugin
jetty-http2-http-client-transport
jetty-http2-server
jetty
jetty-proxy
jetty-xml
jetty-httpservice
jetty-osgi-boot
jetty-client
jetty-spring
jetty-project
jetty-javadoc
jetty-continuation
jetty-nosql
jetty-webapp
jetty-javax-websocket-server-impl
jetty-plus
jetty-osgi-boot-warurl
jetty-websocket-server
jetty-io
jetty-server
jetty-unixsocket
jetty-websocket-api
jetty-jaspi
jetty-websocket-common
jetty-servlet
jetty-annotations
jetty-deploy
jetty-alpn-server
jetty9 (Debian package)
IBM InfoSphere Information Server
How to mitigate CVE-2022-2047
Installation Manager - update to 1.10.1.0
IBM Process Mining - update to 1.13.1
Rational Change - update to 5.3.2.5
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
Netcool/OMNIbus - update to 8.1.0.30
IBM Security Verify Information Queue - update to 10.0.5
IBM Integration Bus - update to 10.1.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.16, 22.0.1.6
Log Analysis - addressed in versions 1.3.7.2 IF001, 1.3.7.2 IF002
Netcool Operations Insight - update to 1.6.10
Cloud Pak for Security (CP4S) - update to 1.10.14.0
IBM Cloud Pak for Data System - update to 2.0.2.1
AMQ Streams - update to 2.3.0
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
User Entity Behavior Analytics - update to 5.0.2
StreamSets Data Collector - update to 7.0.0
IBM Maximo Asset Management - update to 7.6.1.3.0.4
AMQ Broker - update to 7.11.0
IBM Maximo Application Suite - addressed in versions 8.4.6, 8.5
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 41, 8.11.0.1 Interim fix 21, 8.11.1 Interim fix 10, 8.12.0 Interim fix 2
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
jetty-alpn-client - update to 9.4.16-3
jetty-fcgi-server - update to 9.4.16-3
jetty-jsp - update to 9.4.16-3
jetty-quickstart - update to 9.4.16-3
jetty-http2-common - update to 9.4.16-3
jetty-ant - update to 9.4.16-3
jetty-servlets - update to 9.4.16-3
jetty-cdi - update to 9.4.16-3
jetty-util-ajax - update to 9.4.16-3
jetty-jstl - update to 9.4.16-3
jetty-infinispan - update to 9.4.16-3
jetty-http - update to 9.4.16-3
jetty-security - update to 9.4.16-3
jetty-jndi - update to 9.4.16-3
jetty-osgi-alpn - update to 9.4.16-3
jetty-rewrite - update to 9.4.16-3
jetty-http-spi - update to 9.4.16-3
jetty-jspc-maven-plugin - update to 9.4.16-3
jetty-start - update to 9.4.16-3
jetty-http2-hpack - update to 9.4.16-3
jetty-websocket-client - update to 9.4.16-3
jetty-jmx - update to 9.4.16-3
jetty-fcgi-client - update to 9.4.16-3
jetty-http2-client - update to 9.4.16-3
jetty-osgi-boot-jsp - update to 9.4.16-3
jetty-websocket-servlet - update to 9.4.16-3
jetty-jaas - update to 9.4.16-3
jetty-util - update to 9.4.16-3
jetty-javax-websocket-client-impl - update to 9.4.16-3
jetty-maven-plugin - update to 9.4.16-3
jetty-http2-http-client-transport - update to 9.4.16-3
jetty-http2-server - update to 9.4.16-3
jetty - update to 9.4.16-3
jetty-proxy - update to 9.4.16-3
jetty-xml - update to 9.4.16-3
jetty-httpservice - update to 9.4.16-3
jetty-osgi-boot - update to 9.4.16-3
jetty-client - update to 9.4.16-3
jetty-spring - update to 9.4.16-3
jetty-project - update to 9.4.16-3
jetty-javadoc - update to 9.4.16-3
jetty-continuation - update to 9.4.16-3
jetty-nosql - update to 9.4.16-3
jetty-webapp - update to 9.4.16-3
jetty-javax-websocket-server-impl - update to 9.4.16-3
jetty-plus - update to 9.4.16-3
jetty-osgi-boot-warurl - update to 9.4.16-3
jetty-websocket-server - update to 9.4.16-3
jetty-io - update to 9.4.16-3
jetty-server - update to 9.4.16-3
jetty-unixsocket - update to 9.4.16-3
jetty-websocket-api - update to 9.4.16-3
jetty-jaspi - update to 9.4.16-3
jetty-websocket-common - update to 9.4.16-3
jetty-servlet - update to 9.4.16-3
jetty-annotations - update to 9.4.16-3
jetty-deploy - update to 9.4.16-3
jetty-alpn-server - update to 9.4.16-3
jetty9 (Debian package) - update to 9.4.39-3+deb11u1
jetty - update to 9.4.43-6
jetty-client - update to 9.4.43-6
jetty-continuation - update to 9.4.43-6
jetty-http - update to 9.4.43-6
jetty-io - update to 9.4.43-6
jetty-jaas - update to 9.4.43-6
jetty-javadoc - update to 9.4.43-6
jetty-jmx - update to 9.4.43-6
jetty-security - update to 9.4.43-6
jetty-server - update to 9.4.43-6
jetty-xml - update to 9.4.43-6
jetty-webapp - update to 9.4.43-6
jetty-util-ajax - update to 9.4.43-6
jetty-util - update to 9.4.43-6
jetty-servlet - update to 9.4.43-6
IBM Security Verify Governance - update to 10.0.1.0.3
IBM Spectrum Protect Plus - update to 10.1.14
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
webMethods BPM - addressed in versions 10.15 Fix 15, 11.1 Fix 3
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
External References
Related Security Bulletins
- Multiple vulnerabilities in Eclipse Jetty
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- Debian update for jetty9
- IBM Rational Functional Tester update for Eclipse Jetty
- Multiple vulnerabilities in IBM Rational Change
- Input validation error in IBM Process Mining
- Multiple vulnerabilities in IBM QRadar SIEM
- Security restrictions bypass in IBM Operations Analytics - Log Analysis
- IBM Rational Service Tester update for Eclipse Jetty
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Tivoli Netcool/Omnibus update for Eclipse Jetty
- Multiple vulnerabilities in IBM Tivoli Network Manager
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in Red Hat AMQ Streams
- Input validation error in IBM Maximo Application Suite
- Input validation error in IBM Maximo Asset Management
- Input validation error in IBM Cloud Pak for Data System
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM Security Verify Information Queue
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM App Connect Enterprise Toolkit and the IBM Integration Bus Toolkit
- Multiple vulnerabilities in IBM Rational Performance Tester
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- IBM Integration Bus update for Eclipse Jetty
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- openEuler 22.03 LTS SP1 update for jetty
- openEuler 20.03 LTS SP1 update for jetty
- openEuler 20.03 LTS SP3 update for jetty
- openEuler 22.03 LTS update for jetty
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- Multiple vulnerabilities in IBM Installation Manager
- Anolis OS update for jetty
- Anolis OS update for jetty
- Anolis OS update for jetty
- Anolis OS update for jetty
- Anolis OS update for jetty
- Multiple vulnerabilities in IBM Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in IBM User Entity Behavior Analytics
- Multiple vulnerabilities in IBM StreamSets Data Collector
- Multiple vulnerabilities in IBM webMethods BPM