Incorrect Regular Expression in UAParser.js - CVE-2022-25927

 

Incorrect Regular Expression in UAParser.js - CVE-2022-25927

Published: March 23, 2023 / Updated: May 21, 2026


Vulnerability identifier: #VU73969
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25927
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation passed via the trim() function. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

UAParser.js
Db2 Intelligence Center
IBM Business Automation Manager Open Editions
QRadar Assistant
Migration Toolkit for Containers
Cloud Pak for Security (CP4S)
Jira Software Server
Event Streams
Crowd Server
Crowd Data Center
Jira Service Management Data Center
Jira Service Management Server
Confluence Data Center
Bitbucket Data Center
Jira Software Data Center
Spectrum Discover
IBM Cloud Transformation Advisor
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Maximo for Civil Infrastructure
SecurityCenter
Confluence Server
IBM App Connect Enterprise

How to mitigate CVE-2022-25927

Install update from vendor's website.

UAParser.js - addressed in versions 0.7.33, 1.0.33
Db2 Intelligence Center - update to 1.1.3.0
Migration Toolkit for Containers - update to 1.7.8
Cloud Pak for Security (CP4S) - update to 1.10.15.0
Crowd Server - update to 7.1.4
Crowd Data Center - addressed in versions 6.0.6, 6.1.3, 6.2.0, 7.1.4
Jira Service Management Data Center - addressed in versions 10.3.17, 11.3.0
Jira Service Management Server - addressed in versions 10.3.17, 11.3.0
SecurityCenter - addressed in versions SC-202505.1, SC-202506.1, 6.6.0
Confluence Server - addressed in versions 9.2.14, 10.2.3
IBM Business Automation Manager Open Editions - update to 9.1.1
Confluence Data Center - addressed in versions 9.2.14, 10.2.3
Bitbucket Data Center - addressed in versions 9.4.18, 10.2.0
Jira Software Data Center - addressed in versions 10.3.17, 11.3.0
Jira Software Server - addressed in versions 10.3.17, 11.3.0
Event Streams - update to 11.1.5
IBM App Connect Enterprise - update to 12.0.8.0
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
IBM Cloud Transformation Advisor - update to 3.4.2
QRadar Assistant - update to 3.6.1
QRadar User Behavior Analytics - update to 4.1.11
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
App Connect Enterprise Certified Container - addressed in versions 5.0.4, 7.1.0
IBM Maximo for Civil Infrastructure - update to 8.5.0

External References

Related Security Bulletins