Input validation error in decode-uri-component - CVE-2022-38900

 

Input validation error in decode-uri-component - CVE-2022-38900

Published: February 15, 2023


Vulnerability identifier: #VU72247
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38900
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

decode-uri-component
DB2 Data Management Console
IBM Business Automation Manager Open Editions
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
Cloud Pak for Network Automation
QRadar Assistant
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Fedora
Migration Toolkit for Containers
SecureTransport
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Confluence Data Center
Spectrum Discover
IBM Cloud Pak for Multicloud Management Security Services
IBM Cloud Transformation Advisor
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Maximo Application Suite
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
pcs
pcs (Red Hat package)
yarnpkg
nodejs-nodemon
rh-nodejs14 (Red Hat package)
npm
nodejs
nodejs-devel
nodejs-full-i18n
nodejs-docs
rh-nodejs14-nodejs (Red Hat package)
nodejs-packaging
Cloud Pak for Security (CP4S)
Cloud Pak for Data
IBM Cloud Pak System
IBM QRadar Use Case Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Cognos Analytics

How to mitigate CVE-2022-38900

Install updates from vendor's website.

decode-uri-component - update to 0.2.1
Migration Toolkit for Containers - update to 1.7.8
DB2 Data Management Console - update to 3.1.13.2
SecureTransport - update to 5.5-20221222
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.4
Confluence Data Center - addressed in versions 7.19.29, 8.5.17, 8.9.8, 9.1.1
IBM Business Automation Manager Open Editions - update to 8.0.3
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
pcs - addressed in versions 0.11.6-1.fc37, 0.11.6-1.fc38, 0.11.6-1.fc39
pcs (Red Hat package) - update to 0.11.6-3.el9
Cognos Analytics Mobile (iOS) - update to 1.1.20
Cognos Analytics Mobile (Android) - update to 1.1.20
Cloud Pak for Security (CP4S) - update to 1.10.12.0
yarnpkg - addressed in versions 1.22.19-5.el9, 1.22.19-5.fc36, 1.22.19-5.fc37, 1.22.19-5.fc38
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
nodejs-nodemon - update to 2.0.20-3
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
Cloud Pak for Network Automation - update to 2.4.3
IBM Cloud Transformation Advisor - update to 3.4.1
QRadar Assistant - update to 3.6.1
rh-nodejs14 (Red Hat package) - update to 3.6-2.el7
IBM QRadar Use Case Manager - update to 3.8.0
QRadar User Behavior Analytics - update to 4.1.13
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.2
Cloud Pak for Data - update to 4.8.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
App Connect Enterprise Certified Container - addressed in versions 5.0.6, 8.1.0
npm - update to 6.14.18-1.14.21.3.1.0.1
IBM Maximo Application Suite - addressed in versions 8.8.7, 8.9.3
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4.1 IF1
nodejs - update to 14.21.3-1.0.1
nodejs-devel - update to 14.21.3-1.0.1
nodejs-full-i18n - update to 14.21.3-1.0.1
nodejs-docs - update to 14.21.3-1.0.1
rh-nodejs14-nodejs (Red Hat package) - update to 14.21.3-2.el7
nodejs-packaging - update to 23-3

External References

Related Security Bulletins