Incorrect Regular Expression in marked - CVE-2022-21681
Published: May 12, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
IBM Business Automation Manager Open Editions
Storage Defender – Data Protect
Cloud Pak for Multicloud Management Infrastructure Management
Storage Ceph
IBM Cloud Automation Manager
IBM Maximo Asset Management
Maximo Manage Application in IBM Maximo Application Suite
IBM Spectrum Protect Plus
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
golang-github-hashicorp-consul-sdk
gitqlient
golang-github-hashicorp-consul-api
Red Hat Ceph Storage
IBM Cognos Analytics
How to mitigate CVE-2022-21681
IBM Business Automation Manager Open Editions - update to 8.0.7
golang-github-hashicorp-consul-sdk - addressed in versions 0.13.0-1.fc36, 0.13.0-1.fc37
Storage Defender – Data Protect - update to 1.4.1
gitqlient - addressed in versions 1.5.0-2.el8, 1.5.0-2.fc36
golang-github-hashicorp-consul-api - addressed in versions 1.18.0-1.fc36, 1.18.0-1.fc37
Cloud Pak for Multicloud Management Infrastructure Management - update to 2.3 Fix Pack 5
Red Hat Ceph Storage - update to 6.1
Storage Ceph - update to 6.1
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.29, 7.6.1.3.4
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.4.6, 8.5
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4.1 IF1
External References
Related Security Bulletins
- Multiple vulnerabilities in IBM Cognos Analytics
- Incorrect Regular Expression in IBM Cloud Automation Manager
- Multiple vulnerabilities in Red Hat Ceph Storage
- Multiple vulnerabilities in IBM Maximo Asset Management
- Multiple vulnerabilities in IBM Maximo Manage application in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in IBM Storage Ceph
- Fedora 36 update for gitqlient
- Fedora EPEL 8 update for gitqlient
- Fedora 36 update for golang-github-hashicorp-consul-sdk
- Fedora 37 update for golang-github-hashicorp-consul-sdk
- Fedora 37 update for golang-github-hashicorp-consul-api
- Fedora 36 update for golang-github-hashicorp-consul-api
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- IBM Cloud Pak for Multicloud Management Infrastructure Management update for Node.js marked
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions