Code Injection in node-sqlite3 - CVE-2022-43441
Published: March 17, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in the Statement Bindings functionality. A remote attacker can use a specially crafted Javascript file and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
IBM VM Recovery Manager DR
IBM VM Recovery Manager HA GUI
Debian Linux
QRadar Pulse App
node-sqlite3 (Debian package)
How to mitigate CVE-2022-43441
QRadar Pulse App - update to 2.2.10
node-sqlite3 (Debian package) - update to 5.0.0+ds1-1+deb11u2