Uncaught Exception in engine.io - CVE-2022-41940
Published: June 16, 2023
Vulnerability identifier: #VU77489
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41940
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform denial of service attacks.
The vulnerability exists due to an uncaught exception. A remote user can send specially crafted HTTP request to trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.
Affected software
engine.io
Answer Retrieval for Watson Discovery On Prem
Cloud Pak for Security (CP4S)
IBM Cloud Transformation Advisor
App Connect Enterprise Certified Container
Fuse
Answer Retrieval for Watson Discovery On Prem
Cloud Pak for Security (CP4S)
IBM Cloud Transformation Advisor
App Connect Enterprise Certified Container
Fuse
How to mitigate CVE-2022-41940
Install updates from vendor's website.
engine.io - update to 6.2.1
Cloud Pak for Security (CP4S) - update to 1.10.8.0
Answer Retrieval for Watson Discovery On Prem - update to 2.10.0
IBM Cloud Transformation Advisor - update to 3.4.1
App Connect Enterprise Certified Container - addressed in versions 5.0.2, 6.2.0
Fuse - update to 7.12.0
Cloud Pak for Security (CP4S) - update to 1.10.8.0
Answer Retrieval for Watson Discovery On Prem - update to 2.10.0
IBM Cloud Transformation Advisor - update to 3.4.1
App Connect Enterprise Certified Container - addressed in versions 5.0.2, 6.2.0
Fuse - update to 7.12.0