Improper input validation in Oracle WebLogic Server - CVE-2022-40153

 

Improper input validation in Oracle WebLogic Server - CVE-2022-40153

Published: January 18, 2023


Vulnerability identifier: #VU71314
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40153
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Centralized Third Party Jars (XStream) component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to perform a denial of service (DoS) attack.


Affected software

Oracle WebLogic Server
API Gateway
API Manager
IBM Data Risk Manager
IBM Cloud Transformation Advisor
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
Netcool Operations Insight
Red Hat Integration Camel Extensions for Quarkus
IBM Sterling B2B Integrator
IBM Tivoli Business Service Manager
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
DataStage on Cloud Pak for Data
PowerStore T
IBM Tivoli Netcool Configuration Manager
Robotic Process Automation for Cloud Pak
SecureTransport
IBM Disconnected Log Collector
IBM Content Navigator
IBM Qradar SIEM
RSA Authentication Manager
Operational Decision Manager
IBM InfoSphere Information Server

How to mitigate CVE-2022-40153

Install updates from vendor's website.

API Manager - update to November 2022
API Gateway - update to November 2022
IBM Cloud Transformation Advisor - update to 3.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
DataStage on Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
SecureTransport - addressed in versions 5.5-20221222, 5.5-20230126
Netcool Operations Insight - update to 1.6.8
IBM Disconnected Log Collector - update to 1.8.3
IBM Data Risk Manager - update to 2.0.6.16
Red Hat Integration Camel Extensions for Quarkus - update to 2.13.2
IBM Content Navigator - update to 3.0.12.4
PowerStore T - update to 3.5.0.1-2083289
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.1.4, 6.1.2.3, 6.2.0.0
IBM Tivoli Business Service Manager - update to 6.2.0.5
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.17
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
RSA Authentication Manager - update to 8.7 Patch 3
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 38, 8.11.0.1 Interim fix 20, 8.11.1 Interim fix 8
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF014, 22.0.1 IF006, 22.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.15, 22.0.1.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.1, 23.0.1

External References

Related Security Bulletins