Input validation error in protobuf - CVE-2022-3509

 

Input validation error in protobuf - CVE-2022-3509

Published: November 29, 2022 / Updated: March 21, 2024


Vulnerability identifier: #VU69670
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3509
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when parsing textformat data. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

protobuf
ObjectScale
Cloudera Observability with IBM
DataStage on Cloud Pak for Data
Db2 Big SQL
IBM OpenPages with Watson
dashDB Local
IBM Watson Machine Learning Accelerator
PowerVM NovaLink
IBM Planning Analytics Workspace
Answer Retrieval for Watson Discovery On Prem
User Entity Behavior Analytics
Storage Protect Server
Robotic Process Automation for Cloud Pak
IBM TXSeries for Multiplatforms
Engineering Workflow Management
IBM Rational Team Concert
IBM Observability with Instana
Log Analysis
Netcool Operations Insight
IBM Security Guardium Key Lifecycle Manager (GKLM)
Crucible Data Center
Crucible Server
Jira Service Management Server
Jira Service Management Data Center
Splunk User Behavior Analytics (UBA)
IBM Intelligent Operations Center
WebSphere Remote Server
IBM Maximo Application Suite
Jira Software Data Center
IBM Transformation Extender Advanced
IBM MQ
IBM Operations Analytics Predictive Insights
IBM Cloud Pak for Multicloud Management Monitoring
Red Hat Integration - Service Registry
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Tivoli Business Service Manager
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
Maximo Manage Application in IBM Maximo Application Suite
IBM Security Verify Governance
IBM Robotic Process Automation
Gentoo Linux
IBM i
IBM Security Guardium
IBM Edge Application Manager
IBM Disconnected Log Collector
JBoss Enterprise Application Platform
IBM WebSphere Application Server Liberty
IBM Qradar SIEM
Jira Software Server
Event Streams
Juniper Secure Analytics (JSA)
Splunk Enterprise
IBM DB2
Voice Gateway
watsonx.data
IBM Cloud Pak System
dev-java/protobuf-java
IBM Sterling Global Mailbox (GM)
IBM CICS TX Advanced
IBM App Connect Enterprise
IBM CICS TX Standard

How to mitigate CVE-2022-3509

Install updates from vendor's website.

protobuf - addressed in versions 3.16.3, 3.19.6, 3.20.3, 3.21.7
ObjectScale - update to 1.3.0
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001A
Netcool Operations Insight - update to 1.6.15
DataStage on Cloud Pak for Data - update to 4.8.5
Crucible Data Center - update to 4.9.12
Crucible Server - update to 4.9.12
Jira Service Management Server - addressed in versions 4.20.27, 5.4.11
Jira Service Management Data Center - addressed in versions 4.20.27, 5.4.11
Splunk User Behavior Analytics (UBA) - addressed in versions 5.2.1, 5.3.0
JBoss Enterprise Application Platform - update to 7.4.10
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF04
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04
Db2 Big SQL - update to 8.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Maximo Application Suite - addressed in versions 8.8.4, 8.9.1
Jira Software Data Center - addressed in versions 9.4.16, 9.6.0
Jira Software Server - addressed in versions 9.4.16, 9.6.0
IBM MQ - addressed in versions 9.2.0.7, 9.3.0.2
dashDB Local - update to 11.5.9.0
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
IBM Watson Machine Learning Accelerator - update to 1.2.3 601632-wmla
IBM Operations Analytics Predictive Insights - update to 1.3.6.6
IBM Disconnected Log Collector - update to 1.8.3
PowerVM NovaLink - addressed in versions 2.0.1-230201, 2.0.3.1.1-230127, 2.1.0-230209
watsonx.data - update to 2.0.3
IBM Planning Analytics Workspace - update to 2.0.83
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 6
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
Red Hat Integration - Service Registry - update to 2.4.3
Answer Retrieval for Watson Discovery On Prem - update to 2.10.0
dev-java/protobuf-java - update to 3.20.3
QRadar User Behavior Analytics - update to 4.1.12
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.6.3
User Entity Behavior Analytics - update to 5.0.2
App Connect Enterprise Certified Container - addressed in versions 5.0.6, 8.1.0
IBM Sterling Global Mailbox (GM) - addressed in versions 6.0.3.8, 6.1.2.2
IBM Tivoli Business Service Manager - update to 6.2.0.5.4
IBM Tivoli Netcool Impact - update to 7.1.0.29
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Storage Protect Server - update to 8.1.22
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.5.6, 8.6.2
IBM Security Verify Governance - update to 10.0.2
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix13, 11.1.0.0 ifix6
IBM App Connect Enterprise - addressed in versions 11.0.0.20, 12.0.8.0
IBM CICS TX Standard - update to 11.1.0.0 ifix6
Event Streams - update to 11.4.0
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.1, 23.0.1
IBM Robotic Process Automation - addressed in versions 21.0.7.1, 23.0.1

External References

Related Security Bulletins