Input validation error in decode-uri-component - CVE-2022-38900
Published: February 15, 2023
Vulnerability identifier: #VU72247
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38900
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
decode-uri-component
DB2 Data Management Console
IBM Business Automation Manager Open Editions
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
Cloud Pak for Network Automation
QRadar Assistant
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Fedora
Migration Toolkit for Containers
SecureTransport
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Confluence Data Center
Spectrum Discover
IBM Cloud Pak for Multicloud Management Security Services
IBM Cloud Transformation Advisor
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Maximo Application Suite
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
pcs
pcs (Red Hat package)
yarnpkg
nodejs-nodemon
rh-nodejs14 (Red Hat package)
npm
nodejs
nodejs-devel
nodejs-full-i18n
nodejs-docs
rh-nodejs14-nodejs (Red Hat package)
nodejs-packaging
Cloud Pak for Security (CP4S)
Cloud Pak for Data
IBM Cloud Pak System
IBM QRadar Use Case Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Cognos Analytics
DB2 Data Management Console
IBM Business Automation Manager Open Editions
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
Cloud Pak for Network Automation
QRadar Assistant
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Fedora
Migration Toolkit for Containers
SecureTransport
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Confluence Data Center
Spectrum Discover
IBM Cloud Pak for Multicloud Management Security Services
IBM Cloud Transformation Advisor
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Maximo Application Suite
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
pcs
pcs (Red Hat package)
yarnpkg
nodejs-nodemon
rh-nodejs14 (Red Hat package)
npm
nodejs
nodejs-devel
nodejs-full-i18n
nodejs-docs
rh-nodejs14-nodejs (Red Hat package)
nodejs-packaging
Cloud Pak for Security (CP4S)
Cloud Pak for Data
IBM Cloud Pak System
IBM QRadar Use Case Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Cognos Analytics
How to mitigate CVE-2022-38900
Install updates from vendor's website.
decode-uri-component - update to 0.2.1
Migration Toolkit for Containers - update to 1.7.8
DB2 Data Management Console - update to 3.1.13.2
SecureTransport - update to 5.5-20221222
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.4
Confluence Data Center - addressed in versions 7.19.29, 8.5.17, 8.9.8, 9.1.1
IBM Business Automation Manager Open Editions - update to 8.0.3
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
pcs - addressed in versions 0.11.6-1.fc37, 0.11.6-1.fc38, 0.11.6-1.fc39
pcs (Red Hat package) - update to 0.11.6-3.el9
Cognos Analytics Mobile (iOS) - update to 1.1.20
Cognos Analytics Mobile (Android) - update to 1.1.20
Cloud Pak for Security (CP4S) - update to 1.10.12.0
yarnpkg - addressed in versions 1.22.19-5.el9, 1.22.19-5.fc36, 1.22.19-5.fc37, 1.22.19-5.fc38
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
nodejs-nodemon - update to 2.0.20-3
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
Cloud Pak for Network Automation - update to 2.4.3
IBM Cloud Transformation Advisor - update to 3.4.1
QRadar Assistant - update to 3.6.1
rh-nodejs14 (Red Hat package) - update to 3.6-2.el7
IBM QRadar Use Case Manager - update to 3.8.0
QRadar User Behavior Analytics - update to 4.1.13
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.2
Cloud Pak for Data - update to 4.8.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
App Connect Enterprise Certified Container - addressed in versions 5.0.6, 8.1.0
npm - update to 6.14.18-1.14.21.3.1.0.1
IBM Maximo Application Suite - addressed in versions 8.8.7, 8.9.3
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4.1 IF1
nodejs - update to 14.21.3-1.0.1
nodejs-devel - update to 14.21.3-1.0.1
nodejs-full-i18n - update to 14.21.3-1.0.1
nodejs-docs - update to 14.21.3-1.0.1
rh-nodejs14-nodejs (Red Hat package) - update to 14.21.3-2.el7
nodejs-packaging - update to 23-3
Migration Toolkit for Containers - update to 1.7.8
DB2 Data Management Console - update to 3.1.13.2
SecureTransport - update to 5.5-20221222
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.4
Confluence Data Center - addressed in versions 7.19.29, 8.5.17, 8.9.8, 9.1.1
IBM Business Automation Manager Open Editions - update to 8.0.3
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
pcs - addressed in versions 0.11.6-1.fc37, 0.11.6-1.fc38, 0.11.6-1.fc39
pcs (Red Hat package) - update to 0.11.6-3.el9
Cognos Analytics Mobile (iOS) - update to 1.1.20
Cognos Analytics Mobile (Android) - update to 1.1.20
Cloud Pak for Security (CP4S) - update to 1.10.12.0
yarnpkg - addressed in versions 1.22.19-5.el9, 1.22.19-5.fc36, 1.22.19-5.fc37, 1.22.19-5.fc38
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
nodejs-nodemon - update to 2.0.20-3
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
Cloud Pak for Network Automation - update to 2.4.3
IBM Cloud Transformation Advisor - update to 3.4.1
QRadar Assistant - update to 3.6.1
rh-nodejs14 (Red Hat package) - update to 3.6-2.el7
IBM QRadar Use Case Manager - update to 3.8.0
QRadar User Behavior Analytics - update to 4.1.13
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.2
Cloud Pak for Data - update to 4.8.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
App Connect Enterprise Certified Container - addressed in versions 5.0.6, 8.1.0
npm - update to 6.14.18-1.14.21.3.1.0.1
IBM Maximo Application Suite - addressed in versions 8.8.7, 8.9.3
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4.1 IF1
nodejs - update to 14.21.3-1.0.1
nodejs-devel - update to 14.21.3-1.0.1
nodejs-full-i18n - update to 14.21.3-1.0.1
nodejs-docs - update to 14.21.3-1.0.1
rh-nodejs14-nodejs (Red Hat package) - update to 14.21.3-2.el7
nodejs-packaging - update to 23-3
External References
Related Security Bulletins
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Input validation error in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Red Hat Enterprise Linux 8.4 Extended Update Support update for the nodejs:14 module
- Multiple vulnerabilities in Axway SecureTransport (December 2022)
- Input validation error in IBM Maximo Application Suite
- Red Hat Software Collections update for rh-nodejs14-nodejs
- Red Hat Enterprise Linux 8 update for the nodejs:14 module
- Red Hat Enterprise Linux 8.6 Extended Update Support update for the nodejs:14 module
- Multiple vulnerabilities in Oracle Linux
- IBM App Connect Enterprise Certified Container update for decode-uri-component
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Spectrum Discover
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Fedora 36 update for yarnpkg
- Fedora 38 update for yarnpkg
- Fedora 37 update for yarnpkg
- Fedora EPEL 9 update for yarnpkg
- Fedora 39 update for pcs
- Fedora 38 update for pcs
- Fedora 37 update for pcs
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Multiple vulnerabilities in IBM QRadar Use Case Manager
- Red Hat Enterprise Linux 9 update for pcs
- IBM Cloud Pak System update for nodejs decode-uri-component
- Multiple vulnerabilities in IBM QRadar Assistant
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Security Services
- Input validation error in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (Android)
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (iOS)
- Confluence Data Center update for decode-uri-component
- Anolis OS update for nodejs:14 module
- Multiple vulnerabilities in IBM DB2 Data Management Console