Stack-based buffer overflow in hutool - CVE-2022-45688

 

Stack-based buffer overflow in hutool - CVE-2022-45688

Published: June 8, 2023


Vulnerability identifier: #VU77102
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45688
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists in the XML.toJSONObject component. A remote unauthenticated attacker can send a specially crafted JSON or XML data, trigger stack-based buffer overflow and perform a denial of service attack.


Affected software

hutool
Oracle Communications Policy Management
Oracle Banking Digital Experience
Oracle Siebel CRM
ObjectScale
IBM i Modernization Engine for Lifecycle Integration
Storage Copy Data Management
IBM Cloud Pak for Watson AIOps
MobileFirst Platform
Maximo Application Suite - IoT Component
webMethods BPM
IBM Observability with Instana
IBM Process Mining
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
IBM Sterling B2B Integrator
IBM Sterling Control Center
Oracle Communications WebRTC Session Controller
Jira Software Data Center
Oracle SD-WAN Edge
Middleware Common Libraries and Tools
Oracle Middleware Common Libraries and Tools
Netcool Operations Insight
Unified OSS Console Assurance Monitoring (UOCAM)
IBM Cloud Transformation Advisor
IBM Sterling Connect:Direct Web Services
IBM Sterling Partner Engagement Manager
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
Oracle Solaris Cluster
PeopleSoft Enterprise PeopleTools
Jira Software Server
Oracle Service Bus
Oracle Business Process Management Suite
Siebel CRM Administration
Primavera Gateway
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Unified Data Repository
IBM Security Verify Access

How to mitigate CVE-2022-45688

Install updates from vendor's website.

hutool - update to 5.8.11
IBM Process Mining - update to 1.14.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Dell Secure Connect Gateway - update to 5.16
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM Sterling Control Center - addressed in versions 6.2.1.0.15, 6.3.1.0.4
Jira Software Server - addressed in versions 9.4.16, 9.10.0
Jira Software Data Center - addressed in versions 9.4.16, 9.10.0
Oracle Siebel CRM - update to 23.6
ObjectScale - update to 1.4.0
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.2
Netcool Operations Insight - update to 1.6.10
Storage Copy Data Management - update to 2.2.25.0
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.3
IBM Cloud Transformation Advisor - update to 3.7.1
IBM Cloud Pak for Watson AIOps - update to 4.1
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.24, 6.2.0.23, 6.3.0.7
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.9, 6.2.0.7, 6.2.2.2
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202307260922
Maximo Application Suite - IoT Component - addressed in versions 8.7.19, 8.8.15, 9.0.5
IBM Maximo Application Suite - addressed in versions 8.9.6, 8.10.3
IBM Security Verify Access - update to 10.0.7.0
webMethods BPM - update to 11.1 Fix 1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.21, 22.0.2.5

External References

Related Security Bulletins