Out-of-bounds write in xstream - CVE-2022-40151

 

Out-of-bounds write in xstream - CVE-2022-40151

Published: November 14, 2022 / Updated: December 28, 2022


Vulnerability identifier: #VU69283
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40151
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a boundary error if the parser is running on user supplied input. A remote attacker can pass a specially crafted XML input to the application and perform a denial of service attack.


Affected software

xstream
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server Module
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Fedora
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
openEuler
IBM Process Mining
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
Dell Secure Connect Gateway
Atlas eDiscovery Process Management
Red Hat Integration Camel Extensions for Quarkus
IBM Sterling B2B Integrator
IBM Tivoli Business Service Manager
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
SecureTransport
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
IBM Business Automation Manager Open Editions
InfoSphere Data Architect
Storage Copy Data Management
UrbanCode Build
IBM Tivoli Netcool Configuration Manager
Engineering Test Management
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect Client
xstream
xstream-hibernate
xstream-benchmark
xstream-parent
xstream-javadoc
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
IBM Disconnected Log Collector
IBM Data Risk Manager
IBM Content Navigator
Red Hat Camel for Spring Boot
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
IBM FileNet Content Manager
IBM Qradar SIEM
Operational Decision Manager
IBM InfoSphere Information Server

How to mitigate CVE-2022-40151

Install updates from vendor's website.

xstream - update to 1.4.20
IBM Process Mining - update to 1.14.0.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
Dell Secure Connect Gateway - update to 5.14.00.10
SecureTransport - update to 5.5-20221222
Atlas eDiscovery Process Management - update to 6.0.3.9.7
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.5
IBM Business Automation Manager Open Editions - update to 8.0.3
InfoSphere Data Architect - update to 9.2.1
xstream - update to 1.4.20-1
xstream-hibernate - update to 1.4.20-1
xstream-benchmark - update to 1.4.20-1
xstream-parent - update to 1.4.20-1
xstream-javadoc - update to 1.4.20-1
xstream - update to 1.4.20-1.el8
xstream-parent - update to 1.4.20-150200.3.25.1
xstream-benchmark - update to 1.4.20-150200.3.25.1
xstream-javadoc - update to 1.4.20-150200.3.25.1
xstream - update to 1.4.20-150200.3.25.1
IBM Disconnected Log Collector - update to 1.8.3
IBM Data Risk Manager - update to 2.0.6.16
Storage Copy Data Management - update to 2.2.26.0
Red Hat Integration Camel Extensions for Quarkus - update to 2.13.2
jenkins (Red Hat package) - update to 2.387.3.1684911776-3.el8
IBM Content Navigator - update to 3.0.12.4
Red Hat Camel for Spring Boot - update to 3.20.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
jenkins-2-plugins (Red Hat package) - update to 4.13.1684911916-1.el8
IBM FileNet Content Manager - addressed in versions 5.5.4.0 IF0010, 5.5.8.0 IF004, 5.5.9.0 IF002, 5.5.10.0 IF001
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.1.4, 6.1.2.3, 6.2.0.0
UrbanCode Build - update to 6.1.7.10
IBM Tivoli Business Service Manager - update to 6.2.0.5
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.17
Engineering Test Management - addressed in versions 7.0.1.0.23, 7.0.2.0.25
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.20.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.20.0
Storage Protect for Space Management - update to 8.1.20.0
Storage Protect Client - update to 8.1.20.0
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 38, 8.11.0.1 Interim fix 20, 8.11.1 Interim fix 8
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF014, 22.0.1 IF006, 22.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.15, 22.0.1.5

External References

Related Security Bulletins