Improper Authorization in Spring Security - CVE-2022-31692
Published: November 1, 2022
Vulnerability identifier: #VU68866
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31692
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to authorization rules bypass via forward or include dispatcher types. A remote attacker can bypass authorization process.
Affected software
Spring Security
IBM Process Mining
Oracle Communications Unified Inventory Management
Oracle Communications Session Report Manager
Oracle SD-WAN Edge
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
IBM Maximo Application Suite
IBM Common Licensing
NetWorker
IBM Data Risk Manager
Oracle Communications Element Manager
Oracle Banking Liquidity Management
Oracle Banking Trade Finance Process Management
Oracle Banking Virtual Account Management
Oracle Banking Supply Chain Finance
Multicluster Engine for Kubernetes
Red Hat OpenShift Container Platform
Communications Unified Assurance
MySQL Enterprise Monitor
IBM InfoSphere Information Server
Oracle Communications Cloud Native Core Console
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
toolbox (Red Hat package)
cri-o (Red Hat package)
haproxy (Red Hat package)
jenkins (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
jenkins-2-plugins (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
IBM i Modernization Engine for Lifecycle Integration
Dell Policy Manager for Secure Connect Gateway (SCG)
Maximo Data Loader
Fuse
IBM Process Mining
Oracle Communications Unified Inventory Management
Oracle Communications Session Report Manager
Oracle SD-WAN Edge
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
IBM Maximo Application Suite
IBM Common Licensing
NetWorker
IBM Data Risk Manager
Oracle Communications Element Manager
Oracle Banking Liquidity Management
Oracle Banking Trade Finance Process Management
Oracle Banking Virtual Account Management
Oracle Banking Supply Chain Finance
Multicluster Engine for Kubernetes
Red Hat OpenShift Container Platform
Communications Unified Assurance
MySQL Enterprise Monitor
IBM InfoSphere Information Server
Oracle Communications Cloud Native Core Console
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
toolbox (Red Hat package)
cri-o (Red Hat package)
haproxy (Red Hat package)
jenkins (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
jenkins-2-plugins (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
IBM i Modernization Engine for Lifecycle Integration
Dell Policy Manager for Secure Connect Gateway (SCG)
Maximo Data Loader
Fuse
How to mitigate CVE-2022-31692
Install updates from vendor's website.
Spring Security - addressed in versions 5.6.9, 5.7.5
IBM Process Mining - update to 1.14.0.0
IBM Data Risk Manager - update to 2.0.6.15
Multicluster Engine for Kubernetes - update to 2.2.4
Red Hat OpenShift Container Platform - update to 4.10.56
toolbox (Red Hat package) - update to 0.0.9-1.rhaos4.10.el8
IBM i Modernization Engine for Lifecycle Integration - update to 1.4
cri-o (Red Hat package) - addressed in versions 1.23.5-8.rhaos4.10.gitcc8441d.el7, 1.23.5-8.rhaos4.10.gitcc8441d.el8
haproxy (Red Hat package) - update to 2.2.19-4.el8
jenkins (Red Hat package) - update to 2.387.1.1680701869-1.el8
openshift (Red Hat package) - addressed in versions 4.10.0-202303221742.p0.g16bcd69.assembly.stream.el7, 4.10.0-202303221742.p0.g16bcd69.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.10.0-202304032041.p0.g3a7500d.assembly.stream.el7, 4.10.0-202304032041.p0.g3a7500d.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.10.1680703106-1.el8
kernel (Red Hat package) - update to 4.18.0-305.85.1.el8_4
kernel-rt (Red Hat package) - update to 4.18.0-305.85.1.rt7.157.el8_4
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.14.00.14
IBM Sterling B2B Integrator - addressed in versions 6.0.3.8, 6.1.2.2
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
Fuse - update to 7.12.0
Maximo Data Loader - update to 8.5.0
IBM Maximo Application Suite - addressed in versions 8.9.6, 8.10.3
IBM Common Licensing - update to 9.0.0.1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
NetWorker - update to 19.9.0.0
IBM Process Mining - update to 1.14.0.0
IBM Data Risk Manager - update to 2.0.6.15
Multicluster Engine for Kubernetes - update to 2.2.4
Red Hat OpenShift Container Platform - update to 4.10.56
toolbox (Red Hat package) - update to 0.0.9-1.rhaos4.10.el8
IBM i Modernization Engine for Lifecycle Integration - update to 1.4
cri-o (Red Hat package) - addressed in versions 1.23.5-8.rhaos4.10.gitcc8441d.el7, 1.23.5-8.rhaos4.10.gitcc8441d.el8
haproxy (Red Hat package) - update to 2.2.19-4.el8
jenkins (Red Hat package) - update to 2.387.1.1680701869-1.el8
openshift (Red Hat package) - addressed in versions 4.10.0-202303221742.p0.g16bcd69.assembly.stream.el7, 4.10.0-202303221742.p0.g16bcd69.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.10.0-202304032041.p0.g3a7500d.assembly.stream.el7, 4.10.0-202304032041.p0.g3a7500d.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.10.1680703106-1.el8
kernel (Red Hat package) - update to 4.18.0-305.85.1.el8_4
kernel-rt (Red Hat package) - update to 4.18.0-305.85.1.rt7.157.el8_4
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.14.00.14
IBM Sterling B2B Integrator - addressed in versions 6.0.3.8, 6.1.2.2
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
Fuse - update to 7.12.0
Maximo Data Loader - update to 8.5.0
IBM Maximo Application Suite - addressed in versions 8.9.6, 8.10.3
IBM Common Licensing - update to 9.0.0.1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
NetWorker - update to 19.9.0.0
External References
Related Security Bulletins
- Multiple vulnerabilities in VMware Spring Security
- Multiple vulnerabilities in IBM Data Risk Manager
- Improper authorization in IBM Sterling Partner Engagement Manager
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Exposure Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Console
- Multiple vulnerabilities in Oracle Communications Unified Inventory Management
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in Dell Secure Connect Gateway Policy Manager
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Improper authorization in IBM Maximo Data Loader
- Multiple vulnerabilities in OpenShift Container Platform 4.10
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.10
- Multiple vulnerabilities in Oracle SD-WAN Edge
- Multiple vulnerabilities in Oracle Communications Session Report Manager
- Multiple vulnerabilities in Oracle Communications Element Manager
- Improper authorization in IBM Process Mining
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.2
- Improper authorization in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM i Modernization Engine for Lifecycle Integration
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in Oracle Banking Virtual Account Management
- Multiple vulnerabilities in IBM Common Licensing
- Multiple vulnerabilities in Fuse 7
- Multiple vulnerabilities in Oracle Banking Supply Chain Finance
- Multiple vulnerabilities in Oracle Banking Trade Finance Process Management
- Multiple vulnerabilities in Oracle Banking Liquidity Management