Stack-based buffer overflow in Apache Portable Runtime - CVE-2022-28331
Published: February 2, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the apr_socket_sendv() function. A remote attacker can pass specially crafted input to the application, trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Note, the vulnerability affects Windows installations only.
Affected software
IBM Tivoli Monitoring
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Business Automation Manager Open Editions
JBoss Web Server
IBM HTTP Server
Oracle Solaris
PowerScale OneFS
How to mitigate CVE-2022-28331
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
JBoss Web Server - update to 5.7.4
IBM Business Automation Manager Open Editions - update to 9.1.1
IBM HTTP Server - addressed in versions 8.5.5.24, 9.0.5.15
PowerScale OneFS - update to 9.4.0.14
External References
Related Security Bulletins
- Remote code execution in Apache Portable Runtime (APR) on Windows
- Multiple vulnerabilities in IBM HTTP Server
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in Dell EMC PowerScale OneFS
- Multiple vulnerabilities in Red Hat JBoss Web Server 5.7
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for Apache Portable Runtime