Improper input validation in Oracle Communications Cloud Native Core Policy - CVE-2022-3510

 

Improper input validation in Oracle Communications Cloud Native Core Policy - CVE-2022-3510

Published: January 17, 2023


Vulnerability identifier: #VU71253
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3510
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Policy (Google Protobuf-Java) component in Oracle Communications Cloud Native Core Policy. A remote non-authenticated attacker can exploit this vulnerability to perform a denial of service (DoS) attack.


Affected software

Oracle Communications Cloud Native Core Policy
Gentoo Linux
IBM Security Guardium
ObjectScale
DataStage on Cloud Pak for Data
Oracle Business Intelligence Enterprise Edition
Db2 Big SQL
IBM OpenPages with Watson
dashDB Local
IBM Planning Analytics Workspace
Answer Retrieval for Watson Discovery On Prem
Storage Protect Server
IBM Operations Analytics Predictive Insights
Log Analysis
Netcool Operations Insight
IBM Security Guardium Key Lifecycle Manager (GKLM)
Crucible Data Center
Crucible Server
Splunk User Behavior Analytics (UBA)
IBM Intelligent Operations Center
WebSphere Remote Server
IBM MQ
IBM Security Verify Governance
IBM Cloud Pak for Multicloud Management Monitoring
Red Hat Integration - Service Registry
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite
IBM Edge Application Manager
IBM Disconnected Log Collector
Cloudera Data Platform Private Cloud Base for IBM
JBoss Enterprise Application Platform
Splunk Enterprise
IBM DB2
watsonx.data
IBM Cloud Pak System
dev-java/protobuf-java
IBM App Connect Enterprise

How to mitigate CVE-2022-3510

Install updates from vendor's website.

ObjectScale - update to 1.3.0
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001A
Netcool Operations Insight - update to 1.6.15
DataStage on Cloud Pak for Data - update to 4.8.5
Crucible Data Center - update to 4.9.12
Crucible Server - update to 4.9.12
Splunk User Behavior Analytics (UBA) - addressed in versions 5.2.1, 5.3.0
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.7 SP3
JBoss Enterprise Application Platform - update to 7.4.10
Db2 Big SQL - update to 8.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM MQ - addressed in versions 9.2.0.7, 9.3.0.2
dashDB Local - update to 11.5.9.0
IBM Disconnected Log Collector - update to 1.8.3
watsonx.data - addressed in versions 2.0.2, 2.0.3
IBM Planning Analytics Workspace - update to 2.0.83
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 6
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
Red Hat Integration - Service Registry - update to 2.4.3
Answer Retrieval for Watson Discovery On Prem - update to 2.10.0
dev-java/protobuf-java - update to 3.20.3
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
App Connect Enterprise Certified Container - addressed in versions 5.0.6, 8.1.0
IBM Tivoli Business Service Manager - update to 6.2.0.5.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Server - update to 8.1.22
IBM Maximo Application Suite - addressed in versions 8.8.9, 8.9.5, 8.10.1
IBM App Connect Enterprise - addressed in versions 11.0.0.20, 12.0.8.0

External References

Related Security Bulletins