Path traversal in JSZip - CVE-2022-48285

 

Path traversal in JSZip - CVE-2022-48285

Published: March 23, 2023


Vulnerability identifier: #VU73970
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-48285
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to insufficient sanitization of user-supplied in the loadAsync() method. A remote attacker can pass a specially crafted ZIP archive to the application and overwrite arbitrary files on the system.


Affected software

JSZip
Migration Toolkit for Containers
IBM SPSS Analytic Server
Oracle Financial Services Behavior Detection Platform
Oracle Financial Services Model Management and Governance
Oracle Banking APIs
Log Analysis
IBM Safer Payments
IBM Maximo Asset Management
Maximo Manage Application in IBM Maximo Application Suite
Tivoli Network Manager IP Edition
Oracle Business Intelligence Enterprise Edition
Oracle Financial Services Analytical Applications Infrastructure
Oracle Banking Digital Experience
Business Automation Insights
IBM Planning Analytics Workspace
UrbanCode Build
Oracle Utilities Testing Accelerator
Oracle Banking Origination
Oracle Banking Supply Chain Finance
Oracle Banking Liquidity Management
Oracle Banking Credit Facilities Process Management
Primavera Gateway
SIMATIC MV540 H
SIMATIC MV540 S
SIMATIC MV550 H
SIMATIC MV550 S
SIMATIC MV560 U
SIMATIC MV560 X
Dell Storage Manager

How to mitigate CVE-2022-48285

Install update from vendor's website.

JSZip - update to 3.8.0
Migration Toolkit for Containers - update to 1.7.8
Tivoli Network Manager IP Edition - update to 4.2.0.22
Business Automation Insights - addressed in versions 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3
Log Analysis - update to 1.3.8
IBM Planning Analytics Workspace - update to 2.0.91
SIMATIC MV540 H - update to 3.3.4
SIMATIC MV540 S - update to 3.3.4
SIMATIC MV550 H - update to 3.3.4
SIMATIC MV550 S - update to 3.3.4
SIMATIC MV560 U - update to 3.3.4
SIMATIC MV560 X - update to 3.3.4
UrbanCode Build - update to 6.1.7.10
IBM Safer Payments - addressed in versions 6.3.1.04, 6.4.2.03, 6.5.0.01
IBM Maximo Asset Management - addressed in versions 7.6.1.2.31, 7.6.1.3.6
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.4.10, 8.5.6
Dell Storage Manager - update to 2020 R1.21

External References

Related Security Bulletins