Input validation error in xstream - CVE-2022-41966

 

Input validation error in xstream - CVE-2022-41966

Published: December 28, 2022 / Updated: July 16, 2024


Vulnerability identifier: #VU70527
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41966
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass specially crafted data to the application, trigger a stack overflow error and perform a denial of service (DoS) attack.


Affected software

xstream
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server Module
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Fedora
Ubuntu
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
openEuler
Migration Toolkit for Runtimes
Jazz for Service Management
Jira Service Management Server
Jira Service Management Data Center
Red Hat Migration Toolkit for Applications
Atlas eDiscovery Process Management
Oracle Communications Unified Inventory Management
Jira Software Data Center
Oracle Communications Cloud Native Core Binding Support Function
IBM Process Mining
Red Hat Integration Camel Extensions for Quarkus
Red Hat build of Quarkus
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Sterling B2B Integrator
IBM Security Verify Governance
Oracle Utilities Application Framework
Oracle Utilities Testing Accelerator
Oracle SOA Suite
Oracle WebCenter Sites
Application Management Pack for Oracle Utilities & Enterprise Taxation
Oracle Banking Corporate Lending Process Management
Oracle Banking Liquidity Management
Oracle Banking Trade Finance Process Management
Oracle Banking Branch
Oracle Banking Cash Management
Oracle Banking Supply Chain Finance
Oracle Banking Credit Facilities Process Management
IBM Data Risk Manager
Red Hat OpenShift Container Platform
IBM Disconnected Log Collector
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Jira Software Server
IBM Qradar SIEM
Oracle Commerce Guided Search
Oracle Communications BRM - Elastic Charging Engine
IBM InfoSphere Information Server
Oracle Enterprise Manager Ops Center
Oracle Communications Policy Management
Oracle FLEXCUBE Universal Banking
Oracle Retail Xstore Point of Service
Oracle Banking Digital Experience
Storage Copy Data Management
UrbanCode Build
Tivoli Network Configuration Manager IP Edition
IBM Business Automation Manager Open Editions
Oracle Communications Cloud Native Core Console
libxstream-java (Ubuntu package)
libxstream-java (Debian package)
xstream-benchmark
xstream-parent
xstream
xstream-javadoc
xstream-hibernate
cri-o (Red Hat package)
jenkins (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
jenkins-2-plugins (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
Red Hat Camel for Spring Boot
IBM FileNet Content Manager
Fuse

How to mitigate CVE-2022-41966

Install update from vendor's website.

xstream - update to 1.4.20
Migration Toolkit for Runtimes - update to 1.0.2
Red Hat OpenShift Container Platform - update to 4.10.62
Jira Service Management Server - addressed in versions 5.4.18, 5.12.0
Jira Service Management Data Center - addressed in versions 5.4.18, 5.8.0, 5.12.0
Red Hat Migration Toolkit for Applications - update to 6.1.0
Atlas eDiscovery Process Management - update to 6.0.3.9.7
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.5
Jira Software Data Center - addressed in versions 9.4.18, 9.7.2, 9.8.0
Jira Software Server - addressed in versions 9.4.18, 9.7.2, 9.8.0
Oracle Communications BRM - Elastic Charging Engine - update to 12.0.0.7.0
Oracle Banking Corporate Lending Process Management - update to 14.7.0.0.0
Oracle FLEXCUBE Universal Banking - update to 14.7.0.0.0
libxstream-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.11.1-1ubuntu0.3, 1.4.11.1-1+deb10u4build0.18.04.1, 1.4.18-2ubuntu0.1, 1.4.19-1ubuntu0.1
libxstream-java (Debian package) - update to 1.4.15-3+deb11u2
xstream-benchmark - update to 1.4.20-1
xstream-parent - update to 1.4.20-1
xstream - update to 1.4.20-1
xstream-javadoc - update to 1.4.20-1
xstream-hibernate - update to 1.4.20-1
xstream - update to 1.4.20-1.el8
xstream-parent - update to 1.4.20-150200.3.25.1
xstream-benchmark - update to 1.4.20-150200.3.25.1
xstream-javadoc - update to 1.4.20-150200.3.25.1
xstream - update to 1.4.20-150200.3.25.1
IBM Disconnected Log Collector - update to 1.8.3
IBM Process Mining - update to 1.14.0.0
cri-o (Red Hat package) - addressed in versions 1.23.5-16.rhaos4.10.gitbb2cc9a.el7, 1.23.5-16.rhaos4.10.gitbb2cc9a.el8
IBM Data Risk Manager - update to 2.0.6.16
Storage Copy Data Management - update to 2.2.26.0
Red Hat Integration Camel Extensions for Quarkus - update to 2.7-1
Red Hat build of Quarkus - update to 2.7.7
jenkins (Red Hat package) - addressed in versions 2.401.1.1685677065-1.el8, 2.401.1.1686831596-3.el8
Red Hat Camel for Spring Boot - update to 3.20.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.2
openshift-clients (Red Hat package) - addressed in versions 4.10.0-202306081029.p0.g3a7500d.assembly.stream.el7, 4.10.0-202306081029.p0.g3a7500d.assembly.stream.el8
openshift (Red Hat package) - addressed in versions 4.10.0-202306081029.p0.g16bcd69.assembly.stream.el7, 4.10.0-202306081029.p0.g16bcd69.assembly.stream.el8
openshift-ansible (Red Hat package) - addressed in versions 4.10.0-202306081029.p0.g72c7be6.assembly.stream.el7, 4.10.0-202306081029.p0.g72c7be6.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.10.1685679861-1.el8, 4.11.1686831822-1.el8
kernel (Red Hat package) - update to 4.18.0-305.93.1.el8_4
kernel-rt (Red Hat package) - update to 4.18.0-305.93.1.rt7.168.el8_4
IBM Spectrum Control - update to 5.4.10.1
IBM FileNet Content Manager - addressed in versions 5.5.4.0 IF0010, 5.5.8.0 IF004, 5.5.9.0 IF002, 5.5.10.0 IF001
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.1.4, 6.1.2.3, 6.2.0.0
UrbanCode Build - update to 6.1.7.10
Tivoli Network Configuration Manager IP Edition - update to 6.4.2.19
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
Fuse - update to 7.12.0
IBM Business Automation Manager Open Editions - update to 8.0.5
IBM Security Verify Governance - update to 10.0.2
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins