Path traversal in Apache Ivy - CVE-2022-37866
Published: April 26, 2023
Vulnerability identifier: #VU75501
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-37866
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can trick the victim into downloading a specially crafted artifact and write files to an arbitrary location on the system.
Affected software
Apache Ivy
Red Hat Camel for Spring Boot
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Db2 Graph
IBM Cloud Pak for Watson AIOps
Amazon Linux AMI
Fedora
Netcool Operations Insight
apache-ivy
IBM Cloud Pak System
Red Hat Camel for Spring Boot
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Db2 Graph
IBM Cloud Pak for Watson AIOps
Amazon Linux AMI
Fedora
Netcool Operations Insight
apache-ivy
IBM Cloud Pak System
How to mitigate CVE-2022-37866
Install update from vendor's website.
Apache Ivy - update to 2.5.1
Db2 Graph - addressed in versions 1.0.0.1562-amd64, 1.0.0.1562-s390x, 1.0.0.1562-ppcle, 1.0.0.1598-amd64, 1.0.0.1598-s390x, 1.0.0.1598-ppcle
Netcool Operations Insight - update to 1.6.8
apache-ivy - addressed in versions 2.2.0-5.3, 2.5.1-1
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
apache-ivy - update to 2.5.1-3.fc38
IBM Cloud Pak for Watson AIOps - update to 3.6.1
Red Hat Camel for Spring Boot - update to 3.20.1
Db2 Graph - addressed in versions 1.0.0.1562-amd64, 1.0.0.1562-s390x, 1.0.0.1562-ppcle, 1.0.0.1598-amd64, 1.0.0.1598-s390x, 1.0.0.1598-ppcle
Netcool Operations Insight - update to 1.6.8
apache-ivy - addressed in versions 2.2.0-5.3, 2.5.1-1
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
apache-ivy - update to 2.5.1-3.fc38
IBM Cloud Pak for Watson AIOps - update to 3.6.1
Red Hat Camel for Spring Boot - update to 3.20.1
External References
Related Security Bulletins
- Path traversal in Apache Ivy
- Multiple vulnerabilities in Red Hat Integration Camel for Spring Boot
- Multiple vulnerabilities in IBM Db2 Graph
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Fedora 38 update for apache-ivy
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in IBM Cloud Pak System
- Amazon Linux AMI update for apache-ivy
- Amazon Linux AMI update for apache-ivy