Input validation error in xmldom - CVE-2022-39353
Published: October 31, 2022
Vulnerability identifier: #VU68843
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-39353
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input within DOM nodes when they are not well-formed. A remote attacker can pass specially crafted input to the application and gain unauthorized access to the application.
Affected software
xmldom
IBM Spectrum Control
App Connect Enterprise Certified Container
IBM Cloud Pak for Business Automation
IBM App Connect Enterprise
Ubuntu
node-xmldom (Ubuntu package)
IBM Cloud Pak for Watson AIOps
IBM Spectrum Control
App Connect Enterprise Certified Container
IBM Cloud Pak for Business Automation
IBM App Connect Enterprise
Ubuntu
node-xmldom (Ubuntu package)
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2022-39353
Install updates from vendor's website.
xmldom - addressed in versions 0.7.7, 0.8.4, 0.9.0 beta.4
IBM Spectrum Control - update to 5.4.9
IBM App Connect Enterprise - update to 12.0.7.0
node-xmldom (Ubuntu package) - addressed in versions 0.1.27+ds-1+deb10u2build0.20.04.1, 0.7.5-1ubuntu0.22.04.1, 0.7.5-1ubuntu0.22.10.1
IBM Cloud Pak for Watson AIOps - update to 3.6.0
App Connect Enterprise Certified Container - addressed in versions 5.0.2, 6.2.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.19, 22.0.2.3
IBM Spectrum Control - update to 5.4.9
IBM App Connect Enterprise - update to 12.0.7.0
node-xmldom (Ubuntu package) - addressed in versions 0.1.27+ds-1+deb10u2build0.20.04.1, 0.7.5-1ubuntu0.22.04.1, 0.7.5-1ubuntu0.22.10.1
IBM Cloud Pak for Watson AIOps - update to 3.6.0
App Connect Enterprise Certified Container - addressed in versions 5.0.2, 6.2.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.19, 22.0.2.3
External References
Related Security Bulletins
- Improper Validation of Consistency within Input in xmldom
- Input validation error in IBM App Connect Enterprise Certified Container
- Input validation error in IBM Spectrum Control
- Input validation error in IBM App Connect Enterprise
- Ubuntu update for node-xmldom
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps