Incorrect default permissions in Postgresql JDBC Driver - CVE-2022-41946

 

Incorrect default permissions in Postgresql JDBC Driver - CVE-2022-41946

Published: November 23, 2022


Vulnerability identifier: #VU69545
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41946
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to application stores files with sensitive information in system's temporary directory. A local user can read the files and gain access to sensitive information.


Affected software

Postgresql JDBC Driver
IBM Security Guardium
Oracle Linux
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
openEuler
Fedora
Analytics Content Hub
IBM Security Verify Information Queue
InfoSphere Data Replication
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Dell EMC PowerStore Family Operating System
IBM Db2 Web Query for i
Cloudera Data Platform Private Cloud Base for IBM
IBM Data Risk Manager
Red Hat Virtualization Manager
SecureTransport
Red Hat Satellite
IBM Tivoli Netcool Impact
IBM Cloud Pak for Business Automation
IBM Cloud Application Business Insights
Netcool Operations Insight
Red Hat Integration Camel-K
Integration Debezium
Red Hat Integration Camel Extensions for Quarkus
Red Hat build of Quarkus
IBM Watson Discovery for IBM Cloud Pak for Data
Dell Secure Connect Gateway
IBM Sterling Connect:Direct Web Services
IBM Security Verify Governance
IBM Observability with Instana
rubygem-foreman_maintain (Red Hat package)
rubygem-hammer_cli_katello (Red Hat package)
ovirt-ansible-collection (Red Hat package)
python-pulp-container (Red Hat package)
rubygem-optimist (Red Hat package)
python-django (Red Hat package)
foreman (Red Hat package)
rubygem-fog-vsphere (Red Hat package)
rubygem-rbvmomi2 (Red Hat package)
python-pulpcore (Red Hat package)
candlepin (Red Hat package)
rubygem-katello (Red Hat package)
ovirt-engine (Red Hat package)
satellite (Red Hat package)
postgresql-jdbc
postgresql-jdbc-javadoc
postgresql-jdbc (Red Hat package)
postgresql-jdbc-help
IBM Disconnected Log Collector
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Fuse
Operational Decision Manager
IBM Security Verify Access

How to mitigate CVE-2022-41946

Install updates from vendor's website.

Postgresql JDBC Driver - addressed in versions 42.2.27, 42.3.8, 42.4.3, 42.5.1
Analytics Content Hub - update to 2.2
SecureTransport - update to 5.5-20221222
Red Hat Satellite - addressed in versions 6.12.3, 6.13
IBM Tivoli Netcool Impact - update to 7.1.0.28
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
IBM Security Verify Information Queue - update to 10.0.5
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.17, 22.0.2.1
IBM Cloud Application Business Insights - addressed in versions 1.1.7.7, 1.1.8.1
rubygem-foreman_maintain (Red Hat package) - update to 1.1.12-1.el8sat
rubygem-hammer_cli_katello (Red Hat package) - update to 1.6.0.2-1.el8sat
Netcool Operations Insight - update to 1.6.8
IBM Disconnected Log Collector - update to 1.8.3
Red Hat Integration Camel-K - update to 1.10.1
Cloud Pak for Security (CP4S) - update to 1.10.10.0
IBM Data Risk Manager - update to 2.0.6.16
Integration Debezium - update to 2.1.4
ovirt-ansible-collection (Red Hat package) - update to 2.4.2-1.el8ev
Cloud Pak for Network Automation - update to 2.4.3
Red Hat Integration Camel Extensions for Quarkus - addressed in versions 2.7-1, 2.13.2-1
Red Hat build of Quarkus - addressed in versions 2.7.7, 2.13.7
python-pulp-container (Red Hat package) - update to 2.10.12-1.el8pc
rubygem-optimist (Red Hat package) - update to 3.0.1-1.el8sat
python-django (Red Hat package) - update to 3.2.16-1.el8pc
foreman (Red Hat package) - update to 3.3.0.21-2.el8sat
rubygem-fog-vsphere (Red Hat package) - update to 3.6.0-1.el8sat
rubygem-rbvmomi2 (Red Hat package) - update to 3.6.0-2.el8sat
IBM Cloud Pak for Watson AIOps - update to 3.6.1
python-pulpcore (Red Hat package) - update to 3.18.16-1.el8pc
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
candlepin (Red Hat package) - update to 4.1.20-1.el8sat
rubygem-katello (Red Hat package) - update to 4.5.0.32-1.el8sat
ovirt-engine (Red Hat package) - update to 4.5.3.7-1.el8ev
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.2
Dell Secure Connect Gateway - update to 5.20.00.10
IBM Sterling Connect:Direct Web Services - addressed in versions 6.0.0.7, 6.1.0.16, 6.2.0.12
satellite (Red Hat package) - update to 6.12.3-1.el8sat
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
Fuse - update to 7.12.0
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 39, 8.11.0.1 Interim fix 21, 8.11.1 Interim fix 9, 8.12.0 Interim fix 1
postgresql-jdbc - addressed in versions 9.4-3.9.1, 42.2.25-150300.3.11.2, 42.2.25-150400.3.9.2
IBM Security Verify Governance - update to 10.0.1.0.5
IBM Security Verify Access - update to 10.0.6.0
postgresql-jdbc-javadoc - update to 42.2.14-2
postgresql-jdbc - update to 42.2.14-2
postgresql-jdbc (Red Hat package) - addressed in versions 42.2.14-2.el8, 42.2.14-2.el8ev, 42.2.27-1.el9
postgresql-jdbc-javadoc - update to 42.2.25-150400.3.9.2
postgresql-jdbc - update to 42.4.1-2
postgresql-jdbc-javadoc - update to 42.4.1-2
postgresql-jdbc-help - update to 42.4.1-2
postgresql-jdbc - update to 42.4.3-1.fc37
IBM Observability with Instana - update to 267

External References

Related Security Bulletins