Deserialization of Untrusted Data in Scala - CVE-2022-36944

 

Deserialization of Untrusted Data in Scala - CVE-2022-36944

Published: December 28, 2022 / Updated: June 22, 2023


Vulnerability identifier: #VU70531
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36944
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data during Java object deserialization. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Scala
IBM Tivoli Netcool Impact
Oracle Financial Services Model Management and Governance
Oracle Communications Network Analytics Data Director
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management Monitoring
Communications Service Catalog and Design
IBM Engineering Requirements Management DOORS Next
Oracle Communications Policy Management
Cloud Pak for Network Automation
Netezza Performance Server Replication Services
IBM Engineering Lifecycle Optimization - Publishing
Oracle Communications BRM - Elastic Charging Engine
Oracle Banking Corporate Lending Process Management
Fedora
AMQ Streams
scala

How to mitigate CVE-2022-36944

Install updates from vendor's website.

Scala - update to 2.13.9
IBM Tivoli Netcool Impact - update to 7.1.0.28
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Oracle Communications BRM - Elastic Charging Engine - update to 12.0.0.7.0
Netcool Operations Insight - update to 1.6.7
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
AMQ Streams - addressed in versions 2.4.0, 2.5.0
Cloud Pak for Network Automation - update to 2.4.3
scala - addressed in versions 2.13.9-1.fc35, 2.13.9-1.fc36
Netezza Performance Server Replication Services - update to 3.0.5.0
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.2.35, 7.0.3.16, 7.1.4 SR1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins