Improper input validation in Oracle WebLogic Server - CVE-2022-40153
Published: January 18, 2023
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Centralized Third Party Jars (XStream) component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to perform a denial of service (DoS) attack.
Affected software
API Gateway
API Manager
IBM Data Risk Manager
IBM Cloud Transformation Advisor
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
Netcool Operations Insight
Red Hat Integration Camel Extensions for Quarkus
IBM Sterling B2B Integrator
IBM Tivoli Business Service Manager
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
DataStage on Cloud Pak for Data
PowerStore T
IBM Tivoli Netcool Configuration Manager
Robotic Process Automation for Cloud Pak
SecureTransport
IBM Disconnected Log Collector
IBM Content Navigator
IBM Qradar SIEM
RSA Authentication Manager
Operational Decision Manager
IBM InfoSphere Information Server
How to mitigate CVE-2022-40153
API Gateway - update to November 2022
IBM Cloud Transformation Advisor - update to 3.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
DataStage on Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
SecureTransport - addressed in versions 5.5-20221222, 5.5-20230126
Netcool Operations Insight - update to 1.6.8
IBM Disconnected Log Collector - update to 1.8.3
IBM Data Risk Manager - update to 2.0.6.16
Red Hat Integration Camel Extensions for Quarkus - update to 2.13.2
IBM Content Navigator - update to 3.0.12.4
PowerStore T - update to 3.5.0.1-2083289
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.1.4, 6.1.2.3, 6.2.0.0
IBM Tivoli Business Service Manager - update to 6.2.0.5
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.17
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
RSA Authentication Manager - update to 8.7 Patch 3
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 38, 8.11.0.1 Interim fix 20, 8.11.1 Interim fix 8
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF014, 22.0.1 IF006, 22.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.15, 22.0.1.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.1, 23.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in Red Hat Integration Camel Extensions for Quarkus
- Improper input validation in IBM Tivoli Netcool Configuration Manager
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in API Gateway and API Manager
- Multiple vulnerabilities in Axway SecureTransport (December 2022)
- Multiple vulnerabilities in Axway SecureTransport (January 2023)
- Multiple vulnerabilities in IBM Tivoli Business Service Manager
- IBM Watson Discovery Cartridge for IBM Cloud Pak for Data update for XStream
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Content Navigator
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Data Risk Manager
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in IBM Disconnected Log Collector
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in IBM Watson Knowledge Catalog