Path traversal in Apache Ivy - CVE-2022-37866

 

Path traversal in Apache Ivy - CVE-2022-37866

Published: April 26, 2023


Vulnerability identifier: #VU75501
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-37866
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can trick the victim into downloading a specially crafted artifact and write files to an arbitrary location on the system.


Affected software

Apache Ivy
Red Hat Camel for Spring Boot
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Db2 Graph
IBM Cloud Pak for Watson AIOps
Amazon Linux AMI
Fedora
Netcool Operations Insight
apache-ivy
IBM Cloud Pak System

How to mitigate CVE-2022-37866

Install update from vendor's website.

Apache Ivy - update to 2.5.1
Db2 Graph - addressed in versions 1.0.0.1562-amd64, 1.0.0.1562-s390x, 1.0.0.1562-ppcle, 1.0.0.1598-amd64, 1.0.0.1598-s390x, 1.0.0.1598-ppcle
Netcool Operations Insight - update to 1.6.8
apache-ivy - addressed in versions 2.2.0-5.3, 2.5.1-1
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
apache-ivy - update to 2.5.1-3.fc38
IBM Cloud Pak for Watson AIOps - update to 3.6.1
Red Hat Camel for Spring Boot - update to 3.20.1

External References

Related Security Bulletins