Memory leak in Jetty - CVE-2022-2191

 

Memory leak in Jetty - CVE-2022-2191

Published: July 27, 2022


Vulnerability identifier: #VU65832
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2191
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak when handling incorrect TLS connections. A remote attacker can force the application to leak memory and perform denial of service attack.


Affected software

Jetty
Rational Change
Rational Service Tester
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
Rational Performance Tester
Packaging Utility
Installation Manager
Oracle Communications Cloud Native Core Unified Data Repository
AMQ Streams
IBM Cognos Command Center
IBM InfoSphere Information Server

How to mitigate CVE-2022-2191

Install updates from vendor's website.

Jetty - addressed in versions 10.0.10, 11.0.10
Rational Change - update to 5.3.2.5
Packaging Utility - update to 1.10.1.1
Installation Manager - update to 1.10.1.1
AMQ Streams - update to 2.3.0
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

External References

Related Security Bulletins