Type Confusion in OpenJ9 - CVE-2022-3676

 

Type Confusion in OpenJ9 - CVE-2022-3676

Published: October 31, 2022


Vulnerability identifier: #VU68844
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3676
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to a type confusion error. A remote attacker can pass specially crafted data to the application, trigger a type confusion error and access or modify memory.


Affected software

OpenJ9
IBM Tivoli Monitoring
IBM Integration Bus
IBM SPSS Collaboration and Deployment Services
z/Transaction Processing Facility ( z/TPF)
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Intelligent Operations Center
IBM Tivoli Business Service Manager
IBM Tivoli Netcool Impact
WebSphere Service Registry and Repository
CICS Transaction Gateway
Rational Application Developer
Rational Functional Tester (RFT)
IBM ILOG CPLEX Optimization Studio (COS)
IBM Cloud Pak for Business Automation
IBM Operations Analytics Predictive Insights
IBM Cloud Transformation Advisor
Content Collector for Email
Content Collector for Microsoft SharePoint
Content Collector for File Systems
IBM Tivoli System Automation Application Manager
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
IBM Sterling Control Center
Tivoli Composite Application Manager for Transactions
IBM TXSeries for Multiplatforms
Netcool/OMNIbus
IBM Cloud Application Performance Management (APM)
IBM Spectrum Protect Storage Agent
IBM Power Hardware Management Console (HMC)
IBM Security Verify Governance
Rational Service Tester
IBM Robotic Process Automation
IBM Security Guardium
Rational Software Architect Designer (RSAD)
IBM WebSphere Application Server Patterns
Rational Synergy
InfoSphere Data Architect
Tivoli System Automation for Multiplatforms
IBM Semeru Runtimes
Rational Business Developer (RBD)
IBM Java SDK
IBM CICS TX Advanced
IBM App Connect Enterprise
IBM CICS TX Standard
IBM Data Risk Manager
IBM Tivoli Application Dependency Discovery Manager
IBM Cloud Pak for Multicloud Management
IBM Sterling Connect:Direct File Agent
IBM Enterprise Content Management System Monitor
IBM VIOS
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
IBM AIX
IBM i
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Legacy Software
openSUSE Leap
Content Manager Enterprise Edition
Event Streams
IBM Qradar SIEM
Voice Gateway
java-1_7_1-ibm
java-1_7_1-ibm-alsa
java-1_7_1-ibm-devel
java-1_7_1-ibm-jdbc
java-1_7_1-ibm-plugin
java-1_8_0-ibm-alsa
java-1_8_0-ibm
java-1_8_0-ibm-devel
java-1_8_0-ibm-plugin
java-1_8_0-ibm-demo
java-1_8_0-ibm-src
java-1_8_0-ibm-32bit
java-1_8_0-ibm-devel-32bit
java-1_8_0-openj9-javadoc
java-1_8_0-openj9
java-1_8_0-openj9-accessibility
java-1_8_0-openj9-debuginfo
java-1_8_0-openj9-debugsource
java-1_8_0-openj9-demo
java-1_8_0-openj9-demo-debuginfo
java-1_8_0-openj9-devel
java-1_8_0-openj9-devel-debuginfo
java-1_8_0-openj9-headless
java-1_8_0-openj9-headless-debuginfo
java-1_8_0-openj9-src
watsonx.data
IBM Cloud Pak System
Liberty for Java for IBM Cloud
IBM Security SOAR

How to mitigate CVE-2022-3676

Install updates from vendor's website.

OpenJ9 - update to 0.35.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.2
IBM Data Risk Manager - update to 2.0.6.15
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Intelligent Operations Center - update to 5.2.4
IBM Tivoli Netcool Impact - update to 7.1.0.28
Rational Synergy - update to 7.2.2.6
Content Manager Enterprise Edition - update to 8.6.0.5
InfoSphere Data Architect - update to 9.2.1
Event Streams - update to 11.1.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.17, 22.0.2.1
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
IBM Operations Analytics Predictive Insights - update to 1.3.6.6
IBM Sterling Connect:Direct File Agent - update to 1.4.0.2.34
java-1_7_1-ibm - update to 1.7.1_sr5.15-38.77.1
java-1_7_1-ibm-alsa - update to 1.7.1_sr5.15-38.77.1
java-1_7_1-ibm-devel - update to 1.7.1_sr5.15-38.77.1
java-1_7_1-ibm-jdbc - update to 1.7.1_sr5.15-38.77.1
java-1_7_1-ibm-plugin - update to 1.7.1_sr5.15-38.77.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr7.20-30.102.1, 1.8.0_sr7.20-150000.3.68.1
java-1_8_0-ibm - addressed in versions 1.8.0_sr7.20-30.102.1, 1.8.0_sr7.20-150000.3.68.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr7.20-30.102.1, 1.8.0_sr7.20-150000.3.68.1
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr7.20-30.102.1, 1.8.0_sr7.20-150000.3.68.1
java-1_8_0-ibm-demo - update to 1.8.0_sr7.20-150000.3.68.1
java-1_8_0-ibm-src - update to 1.8.0_sr7.20-150000.3.68.1
java-1_8_0-ibm-32bit - update to 1.8.0_sr7.20-150000.3.68.1
java-1_8_0-ibm-devel-32bit - update to 1.8.0_sr7.20-150000.3.68.1
java-1_8_0-openj9-javadoc - update to 1.8.0.352-150200.3.27.1
java-1_8_0-openj9 - update to 1.8.0.352-150200.3.27.1
java-1_8_0-openj9-accessibility - update to 1.8.0.352-150200.3.27.1
java-1_8_0-openj9-debuginfo - update to 1.8.0.352-150200.3.27.1
java-1_8_0-openj9-debugsource - update to 1.8.0.352-150200.3.27.1
java-1_8_0-openj9-demo - update to 1.8.0.352-150200.3.27.1
java-1_8_0-openj9-demo-debuginfo - update to 1.8.0.352-150200.3.27.1
java-1_8_0-openj9-devel - update to 1.8.0.352-150200.3.27.1
java-1_8_0-openj9-devel-debuginfo - update to 1.8.0.352-150200.3.27.1
java-1_8_0-openj9-headless - update to 1.8.0.352-150200.3.27.1
java-1_8_0-openj9-headless-debuginfo - update to 1.8.0.352-150200.3.27.1
java-1_8_0-openj9-src - update to 1.8.0.352-150200.3.27.1
watsonx.data - update to 2.0.2
IBM Cloud Pak System - update to 2.3.3.7
IBM Cloud Transformation Advisor - update to 3.4.1
Liberty for Java for IBM Cloud - update to 3.77-20221207-2115
Content Collector for Email - update to 4.0.1.15 IF003
Content Collector for Microsoft SharePoint - update to 4.0.1.15 IF003
Content Collector for File Systems - update to 4.0.1.15 IF003
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.2.0.12, 4.1.0.3.0.9, 4.1.0.4.0.6, 4.1.0.5.0.4
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.4.0.17, 4.1.0.5.0.11, 4.1.0.6.0.6, 4.1.0.7.0.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.2
IBM Enterprise Content Management System Monitor - update to 5.5.7.0.6
IBM Sterling Secure Proxy - update to 6.0.3 iFix 07
IBM Sterling External Authentication Server - addressed in versions 6.0.3.0 iFix 07, 6.1.0.0 iFix 03
IBM Sterling Control Center - addressed in versions 6.1.3.0.15, 6.2.1.0.10, 6.3.0.0.1
IBM Java SDK - addressed in versions 7.0.11.15, 7.1.5.15, 8.0.7.20
Tivoli Composite Application Manager for Transactions - update to 7.4.0.1.63
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
IBM Semeru Runtimes - addressed in versions 8.0.352.0, 11.0.17.0, 17.0.5.0
IBM TXSeries for Multiplatforms - addressed in versions 8.1.0.3, 8.2.0.2, 9.1.0.2
Netcool/OMNIbus - update to 8.1.0.31
IBM Cloud Application Performance Management (APM) - addressed in versions 8.1.4.0.12, 8.1.4.0.14
IBM Spectrum Protect Storage Agent - update to 8.1.19
IBM Power Hardware Management Console (HMC) - addressed in versions 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1
IBM Security Verify Governance - update to 10.0.1.0.4
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix13, 11.1.0.0 ifix6
Rational Service Tester - update to 10.5.2
IBM App Connect Enterprise - addressed in versions 11.0.0.21, 12.0.9.0
IBM CICS TX Standard - update to 11.1.0.0 ifix6
IBM Robotic Process Automation - addressed in versions 21.0.7.1, 23.0.1
IBM Security SOAR - update to 47.1

External References

Related Security Bulletins