OS Command Injection in Hadoop - CVE-2022-25168

 

OS Command Injection in Hadoop - CVE-2022-25168

Published: November 23, 2022


Vulnerability identifier: #VU69531
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25168
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation within the FileUtil.unTar(File, File) API. A remote unauthenticated attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Hadoop
Log Analysis
IBM Watson Knowledge Catalog in Cloud Pak for Data
Netcool Operations Insight
QRadar User Behavior Analytics
IBM Cloud Application Performance Management (APM)
DataStage on Cloud Pak for Data
IBM Cloud Pak for Watson AIOps
IBM Qradar SIEM
openEuler
watsonx.data
hadoop-debugsource
hadoop-client
hadoop-mapreduce-examples
hadoop-yarn
hadoop-hdfs
hadoop-tests
hadoop-common
hadoop-maven-plugin
hadoop-debuginfo
hadoop-common-native
hadoop-devel
libhdfs
hadoop-yarn-security
hadoop
hadoop-httpfs
hadoop-mapreduce
IBM Spectrum Scale
IBM InfoSphere Information Server

How to mitigate CVE-2022-25168

Install updates from vendor's website.

Hadoop - addressed in versions 2.10.2, 3.2.4, 3.3.3
Log Analysis - update to 1.3.7.2 IF001
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
DataStage on Cloud Pak for Data - update to 4.8.5
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 8, 7.5.0 Update Pack 4
Netcool Operations Insight - update to 1.6.7
watsonx.data - update to 2.0.2
hadoop-debugsource - update to 3.3.4-1
hadoop-client - update to 3.3.4-1
hadoop-mapreduce-examples - update to 3.3.4-1
hadoop-yarn - update to 3.3.4-1
hadoop-hdfs - update to 3.3.4-1
hadoop-tests - update to 3.3.4-1
hadoop-common - update to 3.3.4-1
hadoop-maven-plugin - update to 3.3.4-1
hadoop-debuginfo - update to 3.3.4-1
hadoop-common-native - update to 3.3.4-1
hadoop-devel - update to 3.3.4-1
libhdfs - update to 3.3.4-1
hadoop-yarn-security - update to 3.3.4-1
hadoop - update to 3.3.4-1
hadoop-httpfs - update to 3.3.4-1
hadoop-mapreduce - update to 3.3.4-1
IBM Cloud Pak for Watson AIOps - update to 3.6.0
QRadar User Behavior Analytics - update to 4.1.12
IBM Spectrum Scale - update to 5.1.5.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

External References

Related Security Bulletins