Server-Side Request Forgery (SSRF) in Apache Batik - CVE-2022-38398

 

Server-Side Request Forgery (SSRF) in Apache Batik - CVE-2022-38398

Published: September 22, 2022 / Updated: October 4, 2022


Vulnerability identifier: #VU67584
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2022-38398
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input in DefaultExternalResourceSecurity when handling URLs loaded though jar protocol. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

Apache Batik
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
Ubuntu
openEuler
IBM Business Automation Workflow
IBM Intelligent Operations Center
IBM Integration Bus
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
Maximo Manage Application in IBM Maximo Application Suite
IBM Maximo Application Suite
IBM App Connect Enterprise
Red Hat Camel for Spring Boot
libbatik-java (Ubuntu package)
batik
dev-java/batik
batik-help
xmlgraphics-batik
IBM Case Manager
Jazz Reporting Service
Engineering Test Management
IBM Engineering Systems Design Rhapsody
Fuse

How to mitigate CVE-2022-38398

Install updates from vendor's website.

Apache Batik - update to 1.15
IBM Intelligent Operations Center - update to 5.2.4
libbatik-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.10-2~18.04.1, 1.12-1ubuntu0.1, 1.14-1ubuntu0.2, 1.14-2ubuntu0.1
batik - update to 1.7-10.10
dev-java/batik - update to 1.17
batik-help - update to 1.17-1
batik - update to 1.17-1
xmlgraphics-batik - update to 1.17-2.7.1
Red Hat Camel for Spring Boot - update to 3.20.1
IBM Case Manager - update to 5.3.3-IF011
Engineering Test Management - addressed in versions 7.0.1.0.22, 7.0.2.0.22
Jazz Reporting Service - update to 7.0.2 iFix021
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.31, 7.6.1.3.0.6
Fuse - update to 7.12.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Maximo Manage Application in IBM Maximo Application Suite - update to 8.4.7
IBM Maximo Application Suite - update to 8.8.7
IBM Engineering Systems Design Rhapsody - update to 9.0.1.0.5

External References

Related Security Bulletins