Out-of-bounds write in Codehaus Jettison - CVE-2022-45685
Published: January 11, 2023 / Updated: March 21, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack..
The vulnerability exists due to a boundary error when processing crafted JSON data. A remote attacker can pass specially crafted input to the application, trigger an out-of-bounds write and perform a denial of service (DoS) attack.
Affected software
Red Hat Camel for Spring Boot
Debian Linux
Ubuntu
openEuler
ObjectScale
DataStage on Cloud Pak for Data
IBM Engineering Requirements Management DOORS Next
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
UrbanCode Build
IBM Application Suite - IBM Asset Data Dictionary Component
IBM Process Mining
IBM Watson Knowledge Catalog in Cloud Pak for Data
Dell Secure Connect Gateway
IBM Sterling B2B Integrator
Jira Software Data Center
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling External Authentication Server
IBM Sterling Secure Proxy
IBM UrbanCode Release
UCD - IBM UrbanCode Deploy
CICS Transaction Gateway
SecureTransport
PeopleSoft Enterprise PeopleTools
Jira Software Server
IBM Qradar SIEM
Oracle WebLogic Server
libjettison-java (Ubuntu package)
libjettison-java (Debian package)
jettison-javadoc
jettison
IBM Disconnected Log Collector
watsonx.data
IBM Data Risk Manager
IBM Cloud Pak System
How to mitigate CVE-2022-45685
ObjectScale - update to 1.3.0
IBM Process Mining - update to 1.14.0.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
DataStage on Cloud Pak for Data - update to 4.8.5
SecureTransport - update to 5.5-20230126
Dell Secure Connect Gateway - update to 5.16
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.0.8, 6.1.1.4, 6.1.2.3, 6.2.0.0
Jira Software Data Center - addressed in versions 9.4.16, 9.9.0
Jira Software Server - addressed in versions 9.4.16, 9.9.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
libjettison-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.0-1ubuntu0.20.04.1, 1.4.1-1ubuntu0.22.04.1, 1.4.1-1ubuntu0.22.10.1
libjettison-java (Debian package) - update to 1.5.3-1~deb11u1
jettison-javadoc - update to 1.5.4-1
jettison - update to 1.5.4-1
IBM Disconnected Log Collector - update to 1.8.3
watsonx.data - update to 2.0.3
IBM Data Risk Manager - update to 2.0.6.16
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Cloud Pak for Network Automation - update to 2.4.4
IBM Cloud Pak for Watson AIOps - update to 3.6.1
Red Hat Camel for Spring Boot - update to 3.20.6
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
IBM Sterling External Authentication Server - addressed in versions 6.0.3.0 iFix 08, 6.1.0.0 iFix 04
IBM Sterling Secure Proxy - update to 6.0.3 iFix 08
UrbanCode Build - update to 6.1.7.10
IBM UrbanCode Release - update to 6.2.5.11
UCD - IBM UrbanCode Deploy - addressed in versions 6.2.7.20, 7.0.5.15, 7.1.2.11, 7.2.3.4, 7.3.1.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
IBM Application Suite - IBM Asset Data Dictionary Component - addressed in versions 8.9.9, 8.10.4
CICS Transaction Gateway - addressed in versions 9.1.0.3, 9.2.0.2, 9.3.0.0
External References
Related Security Bulletins
- Debian update for libjettison-java
- Multiple vulnerabilities in Jettison
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM CICS Transaction Gateway
- Multiple vulnerabilities in IBM UrbanCode Deploy (UCD)
- Multiple vulnerabilities in Axway SecureTransport (January 2023)
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Process Mining
- Ubuntu update for libjettison-java
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- Multiple vulnerabilities in IBM Sterling External Authentication Server
- Multiple vulnerabilities in IBM Application Suite - IBM Asset Data Dictionary Component
- Multiple vulnerabilities in IBM Data Risk Manager
- Multiple vulnerabilities in IBM UrbanCode Release
- Multiple vulnerabilities in IBM UrbanCode Build
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Multiple vulnerabilities in IBM Disconnected Log Collector
- openEuler update for jettison
- Jira Software Data Center and Server update for jettison
- openEuler 20.03 LTS SP4 update for jettison
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 3.20
- IBM watsonx.data update for Jettison
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Watson Knowledge Catalog
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS and DOORS Web Access