Out-of-bounds write in xstream - CVE-2022-40151
Published: November 14, 2022 / Updated: December 28, 2022
Vulnerability identifier: #VU69283
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40151
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a boundary error if the parser is running on user supplied input. A remote attacker can pass a specially crafted XML input to the application and perform a denial of service attack.
Affected software
xstream
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server Module
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Fedora
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
openEuler
IBM Process Mining
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
Dell Secure Connect Gateway
Atlas eDiscovery Process Management
Red Hat Integration Camel Extensions for Quarkus
IBM Sterling B2B Integrator
IBM Tivoli Business Service Manager
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
SecureTransport
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
IBM Business Automation Manager Open Editions
InfoSphere Data Architect
Storage Copy Data Management
UrbanCode Build
IBM Tivoli Netcool Configuration Manager
Engineering Test Management
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect Client
xstream
xstream-hibernate
xstream-benchmark
xstream-parent
xstream-javadoc
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
IBM Disconnected Log Collector
IBM Data Risk Manager
IBM Content Navigator
Red Hat Camel for Spring Boot
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
IBM FileNet Content Manager
IBM Qradar SIEM
Operational Decision Manager
IBM InfoSphere Information Server
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server Module
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Fedora
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
openEuler
IBM Process Mining
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
Dell Secure Connect Gateway
Atlas eDiscovery Process Management
Red Hat Integration Camel Extensions for Quarkus
IBM Sterling B2B Integrator
IBM Tivoli Business Service Manager
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
SecureTransport
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
IBM Business Automation Manager Open Editions
InfoSphere Data Architect
Storage Copy Data Management
UrbanCode Build
IBM Tivoli Netcool Configuration Manager
Engineering Test Management
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect Client
xstream
xstream-hibernate
xstream-benchmark
xstream-parent
xstream-javadoc
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
IBM Disconnected Log Collector
IBM Data Risk Manager
IBM Content Navigator
Red Hat Camel for Spring Boot
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
IBM FileNet Content Manager
IBM Qradar SIEM
Operational Decision Manager
IBM InfoSphere Information Server
How to mitigate CVE-2022-40151
Install updates from vendor's website.
xstream - update to 1.4.20
IBM Process Mining - update to 1.14.0.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
Dell Secure Connect Gateway - update to 5.14.00.10
SecureTransport - update to 5.5-20221222
Atlas eDiscovery Process Management - update to 6.0.3.9.7
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.5
IBM Business Automation Manager Open Editions - update to 8.0.3
InfoSphere Data Architect - update to 9.2.1
xstream - update to 1.4.20-1
xstream-hibernate - update to 1.4.20-1
xstream-benchmark - update to 1.4.20-1
xstream-parent - update to 1.4.20-1
xstream-javadoc - update to 1.4.20-1
xstream - update to 1.4.20-1.el8
xstream-parent - update to 1.4.20-150200.3.25.1
xstream-benchmark - update to 1.4.20-150200.3.25.1
xstream-javadoc - update to 1.4.20-150200.3.25.1
xstream - update to 1.4.20-150200.3.25.1
IBM Disconnected Log Collector - update to 1.8.3
IBM Data Risk Manager - update to 2.0.6.16
Storage Copy Data Management - update to 2.2.26.0
Red Hat Integration Camel Extensions for Quarkus - update to 2.13.2
jenkins (Red Hat package) - update to 2.387.3.1684911776-3.el8
IBM Content Navigator - update to 3.0.12.4
Red Hat Camel for Spring Boot - update to 3.20.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
jenkins-2-plugins (Red Hat package) - update to 4.13.1684911916-1.el8
IBM FileNet Content Manager - addressed in versions 5.5.4.0 IF0010, 5.5.8.0 IF004, 5.5.9.0 IF002, 5.5.10.0 IF001
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.1.4, 6.1.2.3, 6.2.0.0
UrbanCode Build - update to 6.1.7.10
IBM Tivoli Business Service Manager - update to 6.2.0.5
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.17
Engineering Test Management - addressed in versions 7.0.1.0.23, 7.0.2.0.25
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.20.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.20.0
Storage Protect for Space Management - update to 8.1.20.0
Storage Protect Client - update to 8.1.20.0
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 38, 8.11.0.1 Interim fix 20, 8.11.1 Interim fix 8
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF014, 22.0.1 IF006, 22.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.15, 22.0.1.5
IBM Process Mining - update to 1.14.0.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
Dell Secure Connect Gateway - update to 5.14.00.10
SecureTransport - update to 5.5-20221222
Atlas eDiscovery Process Management - update to 6.0.3.9.7
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.5
IBM Business Automation Manager Open Editions - update to 8.0.3
InfoSphere Data Architect - update to 9.2.1
xstream - update to 1.4.20-1
xstream-hibernate - update to 1.4.20-1
xstream-benchmark - update to 1.4.20-1
xstream-parent - update to 1.4.20-1
xstream-javadoc - update to 1.4.20-1
xstream - update to 1.4.20-1.el8
xstream-parent - update to 1.4.20-150200.3.25.1
xstream-benchmark - update to 1.4.20-150200.3.25.1
xstream-javadoc - update to 1.4.20-150200.3.25.1
xstream - update to 1.4.20-150200.3.25.1
IBM Disconnected Log Collector - update to 1.8.3
IBM Data Risk Manager - update to 2.0.6.16
Storage Copy Data Management - update to 2.2.26.0
Red Hat Integration Camel Extensions for Quarkus - update to 2.13.2
jenkins (Red Hat package) - update to 2.387.3.1684911776-3.el8
IBM Content Navigator - update to 3.0.12.4
Red Hat Camel for Spring Boot - update to 3.20.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
jenkins-2-plugins (Red Hat package) - update to 4.13.1684911916-1.el8
IBM FileNet Content Manager - addressed in versions 5.5.4.0 IF0010, 5.5.8.0 IF004, 5.5.9.0 IF002, 5.5.10.0 IF001
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.1.4, 6.1.2.3, 6.2.0.0
UrbanCode Build - update to 6.1.7.10
IBM Tivoli Business Service Manager - update to 6.2.0.5
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.17
Engineering Test Management - addressed in versions 7.0.1.0.23, 7.0.2.0.25
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.20.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.20.0
Storage Protect for Space Management - update to 8.1.20.0
Storage Protect Client - update to 8.1.20.0
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 38, 8.11.0.1 Interim fix 20, 8.11.1 Interim fix 8
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF014, 22.0.1 IF006, 22.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.15, 22.0.1.5
External References
Related Security Bulletins
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in XStream
- Multiple vulnerabilities in Red Hat Integration Camel Extensions for Quarkus
- Multiple vulnerabilities in IBM Tivoli Netcool Configuration Manager
- Multiple vulnerabilities in IBM Business Automation Workflow
- SUSE update for xstream
- Multiple vulnerabilities in Axway SecureTransport (December 2022)
- Multiple vulnerabilities in IBM Tivoli Business Service Manager
- IBM Watson Discovery Cartridge for IBM Cloud Pak for Data update for XStream
- Multiple vulnerabilities in Red Hat Integration Camel for Spring Boot
- Multiple vulnerabilities in IBM Atlas eDiscovery Process Management
- Out-of-bounds write in IBM Process Mining
- Multiple vulnerabilities in IBM Content Navigator
- Multiple vulnerabilities in IBM InfoSphere Information Server
- OpenShift Developer Tools and Services for OCP 4.13 update for jenkins and jenkins-2-plugins
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in IBM Operational Decision Manager
- Out-of-bounds write in IBM FileNet Content Manager
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Fedora EPEL 8 update for xstream
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Out-of-bounds write in IBM Engineering Test Management (ETM)
- Multiple vulnerabilities in IBM Data Risk Manager
- Multiple vulnerabilities in IBM UrbanCode Build
- Multiple vulnerabilities in IBM Storage Protect Client and IBM Storage Protect for Space Management
- Multiple vulnerabilities in IBM Storage Protect for Virtual Environments
- Multiple vulnerabilities in IBM Disconnected Log Collector
- openEuler update for xstream
- Multiple vulnerabilities in Red Hat Process Automation Manager 7.13
- openEuler 20.03 LTS SP4 update for xstream
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Multiple vulnerabilities in IBM Watson Knowledge Catalog
- Multiple vulnerabilities in IBM InfoSphere Data Architect