Deserialization of Untrusted Data in IBM Java SDK - CVE-2022-40609

 

Deserialization of Untrusted Data in IBM Java SDK - CVE-2022-40609

Published: August 3, 2023


Vulnerability identifier: #VU78901
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40609
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

IBM Java SDK
Engineering Lifecycle Management
Rational Business Developer (RBD)
IBM CICS TX Advanced
IBM App Connect Enterprise
IBM CICS TX Standard
IBM Integration Bus
IBM Tivoli Monitoring
IBM Tivoli Business Service Manager
IBM TXSeries for Multiplatforms
IBM Security Access Manager for Enterprise Single-Sign On
IBM Intelligent Operations Center
IBM Maximo Asset Management
IBM Rational Build Forge
CICS Transaction Gateway
Rational Application Developer
IBM Security Verify Governance
IBM Sterling Transformation Extender
SPSS Statistics
IBM Operations Analytics Predictive Insights
IBM Cloud Transformation Advisor
Content Collector for Microsoft SharePoint
Content Collector for File Systems
Content Collector for Email
IBM Tivoli System Automation Application Manager
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
IBM Sterling Connect:Direct Web Services
IBM Sterling Partner Engagement Manager
IBM Tivoli Netcool Impact
Tivoli Composite Application Manager for Transactions
Netcool/OMNIbus
IBM Power Hardware Management Console (HMC)
IBM Cloud Pak for Business Automation
IBM InfoSphere Information Server
IBM DB2
Rational Software Architect Designer (RSAD)
Rational Synergy
Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines
Tivoli Monitoring for Virtual Environments Base
IBM OpenPages with Watson
InfoSphere Data Architect
B2B Advanced Communications
PowerVM NovaLink
IBM Planning Analytics Workspace
Tivoli System Automation for Multiplatforms
Storage Protect Operations Center
Storage Protect Server
Cognos Transformer
IBM Tivoli Application Dependency Discovery Manager
Sterling Connect:Direct Browser User Interface
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
IBM i
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Legacy Module
openSUSE Leap
IBM Cloud Pak for Multicloud Management
IBM Qradar SIEM
Voice Gateway
java-1_8_0-ibm-alsa
java-1_8_0-ibm-plugin
java-1_8_0-ibm-devel
java-1_8_0-ibm
java-1_8_0-ibm-devel-32bit
java-1_8_0-ibm-32bit
java-1_8_0-ibm-demo
java-1_8_0-ibm-src
Planning Analytics Local
Operational Decision Manager
IBM Cloud Pak System
Liberty for Java for IBM Cloud
IBM FileNet Content Manager
IBM WebSphere Application Server

How to mitigate CVE-2022-40609

Install updates from vendor's website.

IBM Java SDK - addressed in versions 7.1.5.19, 8.0-8.5
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Intelligent Operations Center - update to 5.2.4
Rational Synergy - update to 7.2.2.7
Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines - update to 7.2.10
Tivoli Monitoring for Virtual Environments Base - update to 7.3.7
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
IBM Rational Build Forge - update to 8.0.0.24
InfoSphere Data Architect - update to 9.2.1
B2B Advanced Communications - update to 1.0.0.10
Voice Gateway - addressed in versions 1.0.8.6, 1.0.8.9
IBM Operations Analytics Predictive Insights - update to 1.3.6.7
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-38
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr8.10-30.114.1, 1.8.0_sr8.10-150000.3.80.1
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr8.10-30.114.1, 1.8.0_sr8.10-150000.3.80.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr8.10-30.114.1, 1.8.0_sr8.10-150000.3.80.1
java-1_8_0-ibm - addressed in versions 1.8.0_sr8.10-30.114.1, 1.8.0_sr8.10-150000.3.80.1
java-1_8_0-ibm-devel-32bit - update to 1.8.0_sr8.10-150000.3.80.1
java-1_8_0-ibm-32bit - update to 1.8.0_sr8.10-150000.3.80.1
java-1_8_0-ibm-demo - update to 1.8.0_sr8.10-150000.3.80.1
java-1_8_0-ibm-src - update to 1.8.0_sr8.10-150000.3.80.1
PowerVM NovaLink - addressed in versions 2.0.3.1.1-230726, 2.1.1-230725
Planning Analytics Local - update to 2.0.9.19
IBM Planning Analytics Workspace - update to 2.0.91
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
IBM Cloud Transformation Advisor - update to 3.6.2
Content Collector for Microsoft SharePoint - update to 4.0.1.15 IF006
Content Collector for File Systems - update to 4.0.1.15 IF006
Content Collector for Email - update to 4.0.1.15 IF006
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.2.0.15, 4.1.0.3.0.11, 4.1.0.4.0.8, 4.1.0.5.0.6
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.4.0.19, 4.1.0.5.0.13, 4.1.0.6.0.8, 4.1.0.7.0.6, 4.1.1.0.0.2
Liberty for Java for IBM Cloud - update to 4.2-20230619-0514
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.3
IBM FileNet Content Manager - addressed in versions 5.5.8.0 IF005, 5.5.9.0 IF003
IBM Sterling Secure Proxy - update to 6.0.3 iFix 08
IBM Sterling External Authentication Server - addressed in versions 6.0.3.0 iFix 08, 6.1.0.0 iFix 04
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.20, 6.2.0.19, 6.3.0.3
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.9, 6.2.0.7, 6.2.2.2
IBM Tivoli Netcool Impact - update to 7.1.0.31
Tivoli Composite Application Manager for Transactions - update to 7.4.0.1.65
Netcool/OMNIbus - update to 8.1.0.31
Storage Protect Operations Center - update to 8.1.20
Storage Protect Server - update to 8.1.20
IBM WebSphere Application Server - update to 8.5.5.24
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 47, 8.11.0.1 Interim fix 25, 8.11.1 Interim fix 15, 8.12.0 Interim fix 6
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix20, 11.1.0.0 ifix12
IBM Power Hardware Management Console (HMC) - update to 10.1.1020.0
IBM App Connect Enterprise - addressed in versions 11.0.0.22, 12.0.9.0
IBM CICS TX Standard - update to 11.1.0.0 ifix12
IBM DB2 - addressed in versions 11.1.4.7, 11.5.7, 11.5.8
Cognos Transformer - update to 11.1.7 Fix Pack 8
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.25, 23.0.1.3

External References

Related Security Bulletins