Input validation error in xmldom - CVE-2022-39353

 

Input validation error in xmldom - CVE-2022-39353

Published: October 31, 2022


Vulnerability identifier: #VU68843
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-39353
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficient validation of user-supplied input within DOM nodes when they are not well-formed. A remote attacker can pass specially crafted input to the application and gain unauthorized access to the application.


Affected software

xmldom
IBM Spectrum Control
App Connect Enterprise Certified Container
IBM Cloud Pak for Business Automation
IBM App Connect Enterprise
Ubuntu
node-xmldom (Ubuntu package)
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2022-39353

Install updates from vendor's website.

xmldom - addressed in versions 0.7.7, 0.8.4, 0.9.0 beta.4
IBM Spectrum Control - update to 5.4.9
IBM App Connect Enterprise - update to 12.0.7.0
node-xmldom (Ubuntu package) - addressed in versions 0.1.27+ds-1+deb10u2build0.20.04.1, 0.7.5-1ubuntu0.22.04.1, 0.7.5-1ubuntu0.22.10.1
IBM Cloud Pak for Watson AIOps - update to 3.6.0
App Connect Enterprise Certified Container - addressed in versions 5.0.2, 6.2.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.19, 22.0.2.3

External References

Related Security Bulletins