Out-of-bounds write in Apache Commons BCEL - CVE-2022-42920

 

Out-of-bounds write in Apache Commons BCEL - CVE-2022-42920

Published: December 1, 2022


Vulnerability identifier: #VU69809
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-42920
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input within the API. A remote attacker can create a specially crafted request to the affected application, trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

Apache Commons BCEL
Amazon Linux AMI
Oracle Linux
Gentoo Linux
Oracle Solaris Cluster
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Anolis OS
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
Fedora
IBM Business Automation Workflow
Migration Toolkit for Runtimes
Oracle StorageTek Tape Analytics (STA)
Red Hat Migration Toolkit for Applications
Oracle Financial Services Behavior Detection Platform
Oracle Enterprise Data Quality
IBM Cloud Pak for Business Automation
IBM Sterling B2B Integrator
IBM Maximo Asset Management
Maximo Manage Application in IBM Maximo Application Suite
IBM SPSS Collaboration and Deployment Services
IBM Cloud Pak System
Oracle Utilities Application Framework
Oracle Business Activity Monitoring
Oracle Retail Bulk Data Integration
Oracle Communications MetaSolv Solution
Communications Service Catalog and Design
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Oracle Communications Order and Service Management
RSA Authentication Manager
IBM Business Automation Manager Open Editions
PeopleSoft Enterprise HCM Global Payroll Switzerland
Oracle Communications Policy Management
Oracle Application Testing Suite
Oracle Retail Service Backbone
Integration Designer
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libbcel-java (Ubuntu package)
bcel
bcel-javadoc
bcel (Red Hat package)
rh-maven36-bcel (Red Hat package)
dev-java/bcel
Oracle WebLogic Server
AMQ Streams
Fuse
Oracle WebCenter Portal
Oracle Documaker
Oracle Enterprise Manager for Fusion Middleware
Oracle Retail Financial Integration
Oracle Retail Assortment Planning
Oracle Retail Advanced Inventory Planning
Oracle Retail Merchandising System
Oracle Retail Integration Bus

How to mitigate CVE-2022-42920

Install updates from vendor's website.

Apache Commons BCEL - update to 6.6.0
Migration Toolkit for Runtimes - update to 1.0.1
Red Hat Migration Toolkit for Applications - update to 6.0.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.4
IBM Business Automation Manager Open Editions - update to 8.0.3
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.16, 22.0.1.6
libbcel-java (Ubuntu package) - addressed in versions Ubuntu Pro, 6.5.0-1ubuntu0.1
AMQ Streams - update to 2.7.0
bcel - addressed in versions 5.2-7.2.10, 6.5.0-3
bcel-javadoc - update to 5.2-19
bcel - update to 5.2-19
bcel (Red Hat package) - addressed in versions 5.2-19.el7_9, 6.4.1-9.el9_0, 6.4.1-9.el9_1
bcel - addressed in versions 5.2-28.3.1, 5.2-150200.11.3.1
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
rh-maven36-bcel (Red Hat package) - update to 6.3.1-2.3.el7
bcel - addressed in versions 6.4.1-10.fc35, 6.4.1-10.fc36, 6.5.0-3.fc37
dev-java/bcel - update to 6.6.0
IBM Maximo Asset Management - addressed in versions 7.6.1.2.32, 7.6.1.3.7
Fuse - update to 7.12.0
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.4.5, 8.5.1
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.24
RSA Authentication Manager - update to 8.7 Patch 3

External References

Related Security Bulletins