Input validation error in protobuf - CVE-2022-3509

 

Input validation error in protobuf - CVE-2022-3509

Published: November 29, 2022 / Updated: March 21, 2024


Vulnerability identifier: #VU69670
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-3509
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
protobuf
ObjectScale
Cloudera Observability with IBM
DataStage on Cloud Pak for Data
Db2 Big SQL
IBM OpenPages with Watson
dashDB Local
IBM Watson Machine Learning Accelerator
PowerVM NovaLink
IBM Planning Analytics Workspace
Answer Retrieval for Watson Discovery On Prem
User Entity Behavior Analytics
Storage Protect Server
Robotic Process Automation for Cloud Pak
IBM TXSeries for Multiplatforms
Engineering Workflow Management
IBM Rational Team Concert
IBM Observability with Instana
Log Analysis
Netcool Operations Insight
IBM Security Guardium Key Lifecycle Manager (GKLM)
Crucible Data Center
Crucible Server
Jira Service Management Server
Jira Service Management Data Center
Splunk User Behavior Analytics (UBA)
IBM Intelligent Operations Center
WebSphere Remote Server
IBM Maximo Application Suite
Jira Software Data Center
IBM Transformation Extender Advanced
IBM MQ
IBM Operations Analytics Predictive Insights
IBM Cloud Pak for Multicloud Management Monitoring
Red Hat Integration - Service Registry
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Tivoli Business Service Manager
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
Maximo Manage Application in IBM Maximo Application Suite
IBM Security Verify Governance
IBM Robotic Process Automation
Gentoo Linux
IBM i
IBM Security Guardium
IBM Edge Application Manager
IBM Disconnected Log Collector
JBoss Enterprise Application Platform
IBM WebSphere Application Server Liberty
IBM Qradar SIEM
Jira Software Server
Event Streams
Juniper Secure Analytics (JSA)
Splunk Enterprise
IBM DB2
Voice Gateway
watsonx.data
IBM Cloud Pak System
dev-java/protobuf-java
IBM Sterling Global Mailbox (GM)
IBM CICS TX Advanced
IBM App Connect Enterprise
IBM CICS TX Standard

Detailed vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when parsing textformat data. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


How to mitigate CVE-2022-3509

Install updates from vendor's website.

Sources