Improper Authorization in Spring Security - CVE-2022-31692

 

Improper Authorization in Spring Security - CVE-2022-31692

Published: November 1, 2022


Vulnerability identifier: #VU68866
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31692
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to authorization rules bypass via forward or include dispatcher types. A remote attacker can bypass authorization process.


Affected software

Spring Security
IBM Process Mining
Oracle Communications Unified Inventory Management
Oracle Communications Session Report Manager
Oracle SD-WAN Edge
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
IBM Maximo Application Suite
IBM Common Licensing
NetWorker
IBM Data Risk Manager
Oracle Communications Element Manager
Oracle Banking Liquidity Management
Oracle Banking Trade Finance Process Management
Oracle Banking Virtual Account Management
Oracle Banking Supply Chain Finance
Multicluster Engine for Kubernetes
Red Hat OpenShift Container Platform
Communications Unified Assurance
MySQL Enterprise Monitor
IBM InfoSphere Information Server
Oracle Communications Cloud Native Core Console
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
toolbox (Red Hat package)
cri-o (Red Hat package)
haproxy (Red Hat package)
jenkins (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
jenkins-2-plugins (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
IBM i Modernization Engine for Lifecycle Integration
Dell Policy Manager for Secure Connect Gateway (SCG)
Maximo Data Loader
Fuse

How to mitigate CVE-2022-31692

Install updates from vendor's website.

Spring Security - addressed in versions 5.6.9, 5.7.5
IBM Process Mining - update to 1.14.0.0
IBM Data Risk Manager - update to 2.0.6.15
Multicluster Engine for Kubernetes - update to 2.2.4
Red Hat OpenShift Container Platform - update to 4.10.56
toolbox (Red Hat package) - update to 0.0.9-1.rhaos4.10.el8
IBM i Modernization Engine for Lifecycle Integration - update to 1.4
cri-o (Red Hat package) - addressed in versions 1.23.5-8.rhaos4.10.gitcc8441d.el7, 1.23.5-8.rhaos4.10.gitcc8441d.el8
haproxy (Red Hat package) - update to 2.2.19-4.el8
jenkins (Red Hat package) - update to 2.387.1.1680701869-1.el8
openshift (Red Hat package) - addressed in versions 4.10.0-202303221742.p0.g16bcd69.assembly.stream.el7, 4.10.0-202303221742.p0.g16bcd69.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.10.0-202304032041.p0.g3a7500d.assembly.stream.el7, 4.10.0-202304032041.p0.g3a7500d.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.10.1680703106-1.el8
kernel (Red Hat package) - update to 4.18.0-305.85.1.el8_4
kernel-rt (Red Hat package) - update to 4.18.0-305.85.1.rt7.157.el8_4
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.14.00.14
IBM Sterling B2B Integrator - addressed in versions 6.0.3.8, 6.1.2.2
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
Fuse - update to 7.12.0
Maximo Data Loader - update to 8.5.0
IBM Maximo Application Suite - addressed in versions 8.9.6, 8.10.3
IBM Common Licensing - update to 9.0.0.1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
NetWorker - update to 19.9.0.0

External References

Related Security Bulletins