Inconsistent interpretation of HTTP requests in Go Net - CVE-2022-41721

 

Inconsistent interpretation of HTTP requests in Go Net - CVE-2022-41721

Published: March 6, 2023


Vulnerability identifier: #VU72886
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41721
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP/2 request smuggling attacks.

The vulnerability exists due to improper validation of HTTP/2 requests when using MaxBytesHandler. A remote attacker can send a specially crafted HTTP/2 request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

Go Net
Cloud Pak for Security (CP4S)
Cloud Pak for Data
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
ObjectScale
DB2 Data Management Console
Guardium Data Security Center (GDSC)
Dell EMC Streaming Data Platform
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
DB2 Data Management Console on CPD
Storage Ceph
IBM supplied MQ Advanced container images
IBM Sterling Order Management
IBM Netezza for Cloud Pak for Data
Robotic Process Automation for Cloud Pak
QRadar Suite
Consul Enterprise
Red Hat Advanced Cluster Management for Kubernetes
IBM Concert Software
IBM MQ Operator
IBM Fusion HCI
IBM Cloud Transformation Advisor
Data Replication on Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Match 360
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Cloud Pak for Data Scheduling
Red Hat Migration Toolkit for Applications
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes
IBM Spectrum Protect Plus
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Operations Dashboard
watsonx.data
IBM Cloud Pak for Multicloud Management
Dell EMC Container Storage Modules
Red Hat OpenShift Container Platform
Multicluster Engine for Kubernetes
Fedora
caddy
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2022-41721

Install updates from vendor's website.

Go Net - update to 0.1.1-0.20221104162952-702349b0e862
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.20.0
Consul Enterprise - addressed in versions 1.13.8, 1.14.7, 1.15.3
watsonx.data - update to 2.0.2
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Multicluster Engine for Kubernetes - update to 2.3.2
Red Hat Advanced Cluster Management for Kubernetes - update to 2.8.2
DB2 Data Management Console - update to 3.1.13.1
Guardium Data Security Center (GDSC) - update to 3.7.2
IBM Concert Software - update to 1.0.1
Dell EMC Container Storage Modules - update to 1.6.0
Dell EMC Streaming Data Platform - update to 1.7.0
IBM MQ Operator - addressed in versions 2.0.15, 2.4.3
IBM Fusion HCI - addressed in versions 2.6.1, 2.7.0
caddy - addressed in versions 2.6.4-1.el9, 2.6.4-1.fc37, 2.6.4-1.fc38
IBM Cloud Transformation Advisor - update to 3.8.2
IBM Watson Machine Learning Accelerator - addressed in versions 4.2.0, 4.8.0
IBM Cloud Pak for Watson AIOps - update to 4.4.0
Data Replication on Cloud Pak for Data - update to 4.6.5
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
IBM Match 360 - update to 4.7.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.7
IBM Decision Optimization for Cloud Pak for Data - update to 4.8
IBM Cloud Pak for Data Scheduling - update to 4.8.0
Cloud Pak for Data - update to 4.8.5
Red Hat OpenShift Container Platform - update to 4.13.0
DB2 Data Management Console on CPD - update to 5.1.2
Storage Ceph - update to 6.1
Red Hat Migration Toolkit for Applications - update to 6.2.0
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.10-r2, 9.3.3.1-r2
IBM Sterling Order Management - update to 10.0.0.29
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift - update to 10.1.12.4
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes - update to 10.1.12.4
IBM Spectrum Protect Plus - update to 10.1.15
IBM CICS TX Advanced - update to 11.1.0.0 ifix8
IBM CICS TX Standard - update to 11.1.0.0 ifix8
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.4
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-6
Operations Dashboard - update to 2022.2.1-7-lts

External References

Related Security Bulletins