Memory leak in Jetty - CVE-2022-2191
Published: July 27, 2022
Vulnerability identifier: #VU65832
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2191
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak when handling incorrect TLS connections. A remote attacker can force the application to leak memory and perform denial of service attack.
Affected software
Jetty
Rational Change
Rational Service Tester
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
Rational Performance Tester
Packaging Utility
Installation Manager
Oracle Communications Cloud Native Core Unified Data Repository
AMQ Streams
IBM Cognos Command Center
IBM InfoSphere Information Server
Rational Change
Rational Service Tester
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
Rational Performance Tester
Packaging Utility
Installation Manager
Oracle Communications Cloud Native Core Unified Data Repository
AMQ Streams
IBM Cognos Command Center
IBM InfoSphere Information Server
How to mitigate CVE-2022-2191
Install updates from vendor's website.
Jetty - addressed in versions 10.0.10, 11.0.10
Rational Change - update to 5.3.2.5
Packaging Utility - update to 1.10.1.1
Installation Manager - update to 1.10.1.1
AMQ Streams - update to 2.3.0
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
Rational Change - update to 5.3.2.5
Packaging Utility - update to 1.10.1.1
Installation Manager - update to 1.10.1.1
AMQ Streams - update to 2.3.0
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
External References
Related Security Bulletins
- Multiple vulnerabilities in Eclipse Jetty
- Multiple vulnerabilities in IBM Rational Change
- Memory leak in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Exposure Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Unified Data Repository
- IBM Rational Service Tester update for Eclipse Jetty
- Multiple vulnerabilities in Red Hat AMQ Streams
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Rational Performance Tester
- Multiple vulnerabilities in IBM Installation Manager and IBM Packaging Utility