Code Injection in Apache Commons Text - CVE-2022-42889

 

Code Injection in Apache Commons Text - CVE-2022-42889

Published: October 14, 2022 / Updated: March 25, 2025


Vulnerability identifier: #VU68307
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-42889
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to an insecure variable interpolation when processing untrusted input. A remote attacker can send a specially crafted input and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Note, the vulnerability was dubbed Text4shell.


Affected software

Apache Commons Text
OpenShift Developer Tools and Services
Zoho ManageEngine Desktop Central
PowerStore 9000X
PowerStore 7000X
PowerStore 5000X
PowerStore 3000X
PowerStore 1000X
PowerStoreX OS
Gentoo Linux
Red Hat Enterprise Linux for x86_64
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Oracle Utilities Framework
Oracle Healthcare Master Person Index
Oracle Business Intelligence Enterprise Edition
IBM Business Automation Manager Open Editions
Oracle Retail Xstore Point of Service
Db2 Graph
Answer Retrieval for Watson Discovery On Prem
IBM Cloud Pak for Watson AIOps
PowerFlex rack
IBM Sterling Connect:Direct for Microsoft Windows
Robotic Process Automation for Cloud Pak
API Manager
IBM Data Risk Manager
IBM Db2 Web Query for i
Oracle Financial Services Compliance Studio
Oracle Retail Xstore Office Cloud Service
API Gateway
JBoss Enterprise Application Platform
AMQ Broker
Fuse
Primavera Gateway
AMQ Streams
Visual Studio Code Maven extension
IBM Content Navigator
IBM Operations Analytics Predictive Insights
Log Analysis
Netcool Operations Insight
IBM Process Mining
IBM Spectrum Conductor
Dell Secure Connect Gateway
IBM Sterling Control Center
Red Hat Satellite
UCD - IBM UrbanCode Deploy
Oracle Communications Design Studio
Oracle Healthcare Data Repository
Oracle Communications Diameter Signaling Router
Infrastructure Technology
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Enterprise Manager Base Platform
Management Cloud Engine
IBM Cloud Pak for Multicloud Management Monitoring
Red Hat build of Quarkus
Red Hat Integration Camel Extensions for Quarkus
IBM Cloud Transformation Advisor
IBM Sterling Connect:Direct for UNIX
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM Cloud Application Performance Management (APM)
IBM SPSS Modeler
IBM Cloud Pak for Business Automation
Multicluster Engine for Kubernetes
Red Hat OpenShift Container Platform
IBM Sterling Connect:Direct File Agent
Dell Virtual Storage Integrator for VMware vSphere Client
Communications Unified Assurance
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
Jazz Reporting Service
IBM Cognos Command Center
Oracle Communications Order and Service Management
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
ManageEngine AssetExplorer
Oracle Healthcare Foundation
JD Edwards EnterpriseOne Orchestrator
IBM Security Guardium
Oracle Communications BRM - Elastic Charging Engine
IBM InfoSphere Information Server
Oracle WebCenter Content
Oracle Retail Merchandising System
Oracle Communications Cloud Native Core Unified Data Repository
toolbox (Red Hat package)
rubygem-smart_proxy_container_gateway (Red Hat package)
eap7-jettison (Red Hat package)
eap7-velocity (Red Hat package)
dev-java/commons-text
cri-o (Red Hat package)
eap7-snakeyaml (Red Hat package)
haproxy (Red Hat package)
eap7-jackson-databind (Red Hat package)
eap7-jackson-jaxrs-providers (Red Hat package)
eap7-jackson-modules-java8 (Red Hat package)
eap7-jackson-core (Red Hat package)
eap7-jackson-annotations (Red Hat package)
eap7-jackson-modules-base (Red Hat package)
python-pulp-container (Red Hat package)
jenkins (Red Hat package)
rubygem-foreman_webhooks (Red Hat package)
eap7-resteasy (Red Hat package)
eap7-apache-cxf (Red Hat package)
satellite-clone (Red Hat package)
eap7-hal-console (Red Hat package)
foreman (Red Hat package)
python-pulp-rpm (Red Hat package)
python-pulpcore (Red Hat package)
candlepin (Red Hat package)
eap7-netty (Red Hat package)
rubygem-katello (Red Hat package)
openshift (Red Hat package)
jenkins-2-plugins (Red Hat package)
openshift-clients (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
rubygem-activesupport (Red Hat package)
rubygem-actioncable (Red Hat package)
rubygem-actionmailbox (Red Hat package)
rubygem-actionmailer (Red Hat package)
rubygem-actionpack (Red Hat package)
rubygem-actiontext (Red Hat package)
rubygem-actionview (Red Hat package)
rubygem-activejob (Red Hat package)
rubygem-railties (Red Hat package)
rubygem-rails (Red Hat package)
rubygem-activestorage (Red Hat package)
rubygem-activerecord (Red Hat package)
rubygem-activemodel (Red Hat package)
rubygem-foreman_rh_cloud (Red Hat package)
satellite (Red Hat package)
eap7-wildfly (Red Hat package)
Security Threat Response Manager (STRM)

How to mitigate CVE-2022-42889

Install updates from vendor's website.

Apache Commons Text - update to 1.10.0
API Manager - update to November 2022
API Gateway - update to November 2022
Visual Studio Code Maven extension - update to 0.40.2
Log Analysis - update to 1.3.7.2 IF001
Netcool Operations Insight - update to 1.6.8
IBM Process Mining - update to 1.13.2
IBM Data Risk Manager - update to 2.0.6.15
Multicluster Engine for Kubernetes - update to 2.2.4
Red Hat OpenShift Container Platform - addressed in versions 4.9.59, 4.10.56, 4.10.58
Dell Secure Connect Gateway - update to 5.14.00.10
IBM Sterling Control Center - update to 6.2.1.0.9
Red Hat Satellite - addressed in versions 6.12.1, 6.13
JBoss Enterprise Application Platform - addressed in versions 7.1.9, 7.3.12
UCD - IBM UrbanCode Deploy - addressed in versions 7.1.2.9, 7.2.3.2
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 7 Interim Fix 1, 7.5.0 Update Pack 3 Interim Fix 3
AMQ Broker - update to 7.10.2
Fuse - update to 7.11.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.3
IBM Business Automation Manager Open Editions - update to 8.0.3
JD Edwards EnterpriseOne Orchestrator - update to 9.2.7.2
Zoho ManageEngine Desktop Central - update to 10.1.2228.10
toolbox (Red Hat package) - update to 0.0.9-1.rhaos4.10.el8
Db2 Graph - addressed in versions 1.0.0.1562-amd64, 1.0.0.1562-s390x, 1.0.0.1562-ppcle, 1.0.0.1598-amd64, 1.0.0.1598-s390x, 1.0.0.1598-ppcle
rubygem-smart_proxy_container_gateway (Red Hat package) - update to 1.0.7-1.el8sat
eap7-jettison (Red Hat package) - addressed in versions 1.3.8-2.redhat_00002.1.ep7.el7, 1.5.2-2.redhat_00002.1.el7eap
IBM Sterling Connect:Direct File Agent - update to 1.4.0.2.29
eap7-velocity (Red Hat package) - update to 1.7.0-3.redhat_00006.1.ep7.el7
dev-java/commons-text - update to 1.10.0
Cloud Pak for Security (CP4S) - update to 1.10.5.0
cri-o (Red Hat package) - addressed in versions 1.22.5-18.rhaos4.9.gitbd70b3d.el7, 1.22.5-18.rhaos4.9.gitbd70b3d.el8, 1.23.5-8.rhaos4.10.gitcc8441d.el7, 1.23.5-8.rhaos4.10.gitcc8441d.el8, 1.23.5-10.rhaos4.10.gitcc8441d.el7, 1.23.5-10.rhaos4.10.gitcc8441d.el8
eap7-snakeyaml (Red Hat package) - addressed in versions 1.33.0-1.SP1_redhat_00001.1.el7eap, 1.33.0-1.SP1_redhat_00001.1.ep7.el7
haproxy (Red Hat package) - update to 2.2.19-4.el8
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 6
AMQ Streams - update to 2.7.0
Red Hat build of Quarkus - update to 2.7.7
eap7-jackson-databind (Red Hat package) - addressed in versions 2.8.11.6-2.SP1_redhat_00002.1.ep7.el7, 2.10.4-4.redhat_00004.1.el7eap
Answer Retrieval for Watson Discovery On Prem - update to 2.9.0
eap7-jackson-jaxrs-providers (Red Hat package) - update to 2.10.4-2.redhat_00004.1.el7eap
eap7-jackson-modules-java8 (Red Hat package) - update to 2.10.4-2.redhat_00004.1.el7eap
eap7-jackson-core (Red Hat package) - update to 2.10.4-2.redhat_00004.1.el7eap
eap7-jackson-annotations (Red Hat package) - update to 2.10.4-2.redhat_00004.1.el7eap
eap7-jackson-modules-base (Red Hat package) - update to 2.10.4-4.redhat_00004.1.el7eap
python-pulp-container (Red Hat package) - update to 2.10.10-1.el8pc
Red Hat Integration Camel Extensions for Quarkus - update to 2.13.2
jenkins (Red Hat package) - addressed in versions 2.361.4.1680068660-1.el8, 2.387.1.1680701869-1.el8, 2.387.1.1681718871-1.el8, 2.387.1.1683009763-3.el8, 2.387.1.1683009767-3.el8, 2.387.3.1684911776-3.el8, 2.414.3.1698292201-3.el8, 2.414.3.1698293911-3.el8, 2.414.3.1698298955-3.el8, 2.426.3.1706515686-3.el8, 2.426.3.1706516254-3.el8, 2.426.3.1706516352-3.el8, 2.426.3.1706516929-3.el8
rubygem-foreman_webhooks (Red Hat package) - update to 3.0.5-1.1.el8sat
IBM Content Navigator - addressed in versions 3.0.11.7, 3.0.12.4, 3.0.13
eap7-resteasy (Red Hat package) - addressed in versions 3.0.27-1.Final_redhat_00001.1.ep7.el7, 3.11.6-1.Final_redhat_00001.1.el7eap
eap7-apache-cxf (Red Hat package) - update to 3.1.16-4.redhat_00003.1.ep7.el7
satellite-clone (Red Hat package) - update to 3.2.0-2.el8sat
PowerStoreX OS - update to 3.2.1.6-2476179
eap7-hal-console (Red Hat package) - update to 3.2.17-1.Final_redhat_00001.1.el7eap
foreman (Red Hat package) - update to 3.3.0.18-1.el8sat
IBM Cloud Transformation Advisor - update to 3.3.1
IBM Cloud Pak for Watson AIOps - update to 3.6.0
PowerFlex rack - update to 3.6.0.7
python-pulp-rpm (Red Hat package) - update to 3.18.9-1.el8pc
python-pulpcore (Red Hat package) - update to 3.18.11-1.el8pc
candlepin (Red Hat package) - update to 4.1.18-1.el8sat
eap7-netty (Red Hat package) - addressed in versions 4.1.63-1.Final_redhat_00002.1.ep7.el7, 4.1.63-4.Final_redhat_00002.1.el7eap
IBM Sterling Connect:Direct for UNIX - addressed in versions 4.3.0.1.103, 6.0.0.2.139, 6.1.0.4.69, 6.2.0.5.4
rubygem-katello (Red Hat package) - update to 4.5.0.22-1.el8sat
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.0
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 4.8.0.3.50, 6.0.0.4.58, 6.1.0.2.52, 6.2.0.4.17
openshift (Red Hat package) - addressed in versions 4.9.0-202303250015.p0.g71d09da.assembly.stream.el7, 4.9.0-202303250015.p0.g71d09da.assembly.stream.el8, 4.10.0-202303221742.p0.g16bcd69.assembly.stream.el7, 4.10.0-202303221742.p0.g16bcd69.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.9.1680069756-1.el8, 4.10.1680703106-1.el8, 4.10.1681719745-1.el8, 4.11.1683009941-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1683009955-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1684911916-1.el8, 4.13.1698292274-1.el8, 4.13.1706516346-1.el8, 4.14.1706516441-1.el8
openshift-clients (Red Hat package) - addressed in versions 4.10.0-202304032041.p0.g3a7500d.assembly.stream.el7, 4.10.0-202304032041.p0.g3a7500d.assembly.stream.el8
kernel (Red Hat package) - update to 4.18.0-305.85.1.el8_4
kernel-rt (Red Hat package) - update to 4.18.0-305.85.1.rt7.157.el8_4
rubygem-activesupport (Red Hat package) - update to 6.0.6-1.el8sat
rubygem-actioncable (Red Hat package) - update to 6.0.6-2.el8sat
rubygem-actionmailbox (Red Hat package) - update to 6.0.6-2.el8sat
rubygem-actionmailer (Red Hat package) - update to 6.0.6-2.el8sat
rubygem-actionpack (Red Hat package) - update to 6.0.6-2.el8sat
rubygem-actiontext (Red Hat package) - update to 6.0.6-2.el8sat
rubygem-actionview (Red Hat package) - update to 6.0.6-2.el8sat
rubygem-activejob (Red Hat package) - update to 6.0.6-2.el8sat
rubygem-railties (Red Hat package) - update to 6.0.6-2.el8sat
rubygem-rails (Red Hat package) - update to 6.0.6-2.el8sat
rubygem-activestorage (Red Hat package) - update to 6.0.6-2.el8sat
rubygem-activerecord (Red Hat package) - update to 6.0.6-2.el8sat
rubygem-activemodel (Red Hat package) - update to 6.0.6-2.el8sat
rubygem-foreman_rh_cloud (Red Hat package) - update to 6.0.44-1.el8sat
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
satellite (Red Hat package) - update to 6.12.1-1.el8sat
Jazz Reporting Service - update to 7.0.2 iFix021
eap7-wildfly (Red Hat package) - addressed in versions 7.1.9-2.GA_redhat_00002.1.ep7.el7, 7.3.12-3.GA_redhat_00002.1.el7eap
Security Threat Response Manager (STRM) - update to 7.5.0UP4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
Dell Virtual Storage Integrator for VMware vSphere Client - addressed in versions 9.1.2, 10.0.1
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
IBM InfoSphere Information Server - addressed in versions 11.7.1.0, 11.7.1.4
IBM SPSS Modeler - addressed in versions 18.3.0.0 IF018, 18.4.0.0 IF006
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.22, 22.0.2.6
Robotic Process Automation for Cloud Pak - update to 21.0.7
ManageEngine AssetExplorer - update to 6982

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins