Out-of-bounds write in Codehaus Jettison - CVE-2022-45685

 

Out-of-bounds write in Codehaus Jettison - CVE-2022-45685

Published: January 11, 2023 / Updated: March 21, 2024


Vulnerability identifier: #VU71108
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45685
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack..

The vulnerability exists due to a boundary error when processing crafted JSON data. A remote attacker can pass specially crafted input to the application, trigger an out-of-bounds write and perform a denial of service (DoS) attack.


Affected software

Codehaus Jettison
Red Hat Camel for Spring Boot
Debian Linux
Ubuntu
openEuler
ObjectScale
DataStage on Cloud Pak for Data
IBM Engineering Requirements Management DOORS Next
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
UrbanCode Build
IBM Application Suite - IBM Asset Data Dictionary Component
IBM Process Mining
IBM Watson Knowledge Catalog in Cloud Pak for Data
Dell Secure Connect Gateway
IBM Sterling B2B Integrator
Jira Software Data Center
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling External Authentication Server
IBM Sterling Secure Proxy
IBM UrbanCode Release
UCD - IBM UrbanCode Deploy
CICS Transaction Gateway
SecureTransport
PeopleSoft Enterprise PeopleTools
Jira Software Server
IBM Qradar SIEM
Oracle WebLogic Server
libjettison-java (Ubuntu package)
libjettison-java (Debian package)
jettison-javadoc
jettison
IBM Disconnected Log Collector
watsonx.data
IBM Data Risk Manager
IBM Cloud Pak System

How to mitigate CVE-2022-45685

Install updates from vendor's website.

Codehaus Jettison - update to 1.5.2
ObjectScale - update to 1.3.0
IBM Process Mining - update to 1.14.0.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
DataStage on Cloud Pak for Data - update to 4.8.5
SecureTransport - update to 5.5-20230126
Dell Secure Connect Gateway - update to 5.16
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.0.8, 6.1.1.4, 6.1.2.3, 6.2.0.0
Jira Software Data Center - addressed in versions 9.4.16, 9.9.0
Jira Software Server - addressed in versions 9.4.16, 9.9.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
libjettison-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.0-1ubuntu0.20.04.1, 1.4.1-1ubuntu0.22.04.1, 1.4.1-1ubuntu0.22.10.1
libjettison-java (Debian package) - update to 1.5.3-1~deb11u1
jettison-javadoc - update to 1.5.4-1
jettison - update to 1.5.4-1
IBM Disconnected Log Collector - update to 1.8.3
watsonx.data - update to 2.0.3
IBM Data Risk Manager - update to 2.0.6.16
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Cloud Pak for Network Automation - update to 2.4.4
IBM Cloud Pak for Watson AIOps - update to 3.6.1
Red Hat Camel for Spring Boot - update to 3.20.6
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
IBM Sterling External Authentication Server - addressed in versions 6.0.3.0 iFix 08, 6.1.0.0 iFix 04
IBM Sterling Secure Proxy - update to 6.0.3 iFix 08
UrbanCode Build - update to 6.1.7.10
IBM UrbanCode Release - update to 6.2.5.11
UCD - IBM UrbanCode Deploy - addressed in versions 6.2.7.20, 7.0.5.15, 7.1.2.11, 7.2.3.4, 7.3.1.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
IBM Application Suite - IBM Asset Data Dictionary Component - addressed in versions 8.9.9, 8.10.4
CICS Transaction Gateway - addressed in versions 9.1.0.3, 9.2.0.2, 9.3.0.0

External References

Related Security Bulletins