Improper input validation in Oracle Communications Cloud Native Core Automated Test Suite - CVE-2022-37865

 

Improper input validation in Oracle Communications Cloud Native Core Automated Test Suite - CVE-2022-37865

Published: April 18, 2023


Vulnerability identifier: #VU75226
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-37865
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to damange or delete data.

The vulnerability exists due to improper input validation within the Installation (Apache Ivy) component in Oracle Communications Cloud Native Core Automated Test Suite. A remote non-authenticated attacker can exploit this vulnerability to damange or delete data.


Affected software

Oracle Communications Cloud Native Core Automated Test Suite
Netcool Operations Insight
Amazon Linux AMI
Fedora
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Db2 Graph
IBM Cloud Pak for Watson AIOps
MySQL Enterprise Monitor
IBM Cloud Pak System
apache-ivy
Red Hat Camel for Spring Boot

How to mitigate CVE-2022-37865

Install updates from vendor's website.

Db2 Graph - addressed in versions 1.0.0.1562-amd64, 1.0.0.1562-s390x, 1.0.0.1562-ppcle, 1.0.0.1598-amd64, 1.0.0.1598-s390x, 1.0.0.1598-ppcle
Netcool Operations Insight - update to 1.6.8
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
apache-ivy - update to 2.5.1-1
apache-ivy - update to 2.5.1-3.fc38
IBM Cloud Pak for Watson AIOps - update to 3.6.1
Red Hat Camel for Spring Boot - update to 3.20.1

External References

Related Security Bulletins