Code Injection in vm2 - CVE-2022-25893
Published: December 30, 2022
Vulnerability identifier: #VU70544
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25893
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to usage of prototype lookup for the WeakMap.prototype.set method. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.
Affected software
vm2
Cloud Pak for Security (CP4S)
App Connect Enterprise Certified Container
Cloud Pak for Security (CP4S)
App Connect Enterprise Certified Container
How to mitigate CVE-2022-25893
Install updates from vendor's website.
vm2 - update to 3.9.10
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Cloud Pak for Security (CP4S) - update to 1.10.7.0