Incorrect Regular Expression in Semver - CVE-2022-25883

 

Incorrect Regular Expression in Semver - CVE-2022-25883

Published: August 3, 2023 / Updated: November 30, 2023


Vulnerability identifier: #VU78932
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25883
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation when processing regular expressions. A remote attacker can pass specially crafted data to the application via the new Range function and perform regular expression denial of service (ReDos) attack.


Affected software

Semver
IBM Cloud Pak for Security
IBM Observability with Instana
Migration Toolkit for Runtimes
IBM Process Mining
OpenShift Logging
Confluence Data Center
Bitbucket Data Center
IBM QRadar WinCollect Agent
Jira Service Management Data Center
Jira Software Data Center
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Netcool Operations Insight
IBM Fusion HCI
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
QRadar User Behavior Analytics
Splunk Add-on for Google Cloud Platform
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
Oracle Linux
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Fedora
Security QRadar Offenses Forwarder
DB2 Data Management Console
Storage Fusion Data Foundation
IBM Business Automation Manager Open Editions
Rational Performance Tester
DevOps Test Performance
Business Automation Insights
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
IBM Security QRadar Network Threat Analytics
IBM i Modernization Engine for Lifecycle Integration
Storage Defender – Data Protect
IBM Planning Analytics Workspace
Cloud Pak for Network Automation
QRadar Deployment Intelligence App
QRadar Assistant
IBM Cloud Pak for Watson AIOps
Watson AI Gateway for Cloud Pak for Data
Dell Data Protection Central
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
IBM Edge Application Manager
IBM DataPower Gateway
QRadar Suite
Juniper Secure Analytics (JSA)
IBM Security QRadar Analyst Workflow
Splunk Add-on Builder
Network Observability plugin for the Openshift Console
Splunk Enterprise Security (ES)
IBM Cloud Pak System
JBoss Enterprise Application Platform
Bitbucket Server
Confluence Server
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
eap7 (Red Hat package)
eap7-ironjacamar (Red Hat package)
eap7-jboss-server-migration (Red Hat package)
eap7-jboss-modules (Red Hat package)
eap7-wildfly-elytron (Red Hat package)
yarnpkg
eap7-bouncycastle (Red Hat package)
eap7-jboss-marshalling (Red Hat package)
eap7-undertow (Red Hat package)
eap7-activemq-artemis (Red Hat package)
nodejs-nodemon
eap7-hal-console (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
eap7-resteasy (Red Hat package)
eap7-netty-transport-native-epoll (Red Hat package)
eap7-netty (Red Hat package)
eap7-hibernate (Red Hat package)
eap7-wildfly (Red Hat package)
npm
nodejs-docs
nodejs-full-i18n
nodejs-devel
nodejs
nodejs-packaging
nodejs-packaging-bundler
Event Streams
Jira Software Server
Cloud Pak for Data
IBM InfoSphere Information Server
IBM DB2
Voice Gateway
QRadar Pulse App
IBM QRadar Use Case Manager
IBM Storage Scale System
IBM App Connect Enterprise

How to mitigate CVE-2022-25883

Install update from vendor's website.

Semver - update to 7.5.2
Security QRadar Offenses Forwarder - update to 1.2.0
Migration Toolkit for Runtimes - update to 1.2.4
Migration Toolkit for Containers - update to 1.8.2
QRadar Suite - update to 1.10.19.0
IBM Process Mining - update to 1.14.2
IBM Cloud Pak for Multicloud Management - update to 2.3.8
DB2 Data Management Console - update to 3.1.13.2
Splunk Add-on Builder - update to 4.1.4
Splunk Enterprise Security (ES) - addressed in versions 7.1.2, 7.2.0, 7.3.0
OpenShift Logging - update to 5.7.4
JBoss Enterprise Application Platform - update to 7.4.13
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04
Confluence Data Center - addressed in versions 9.2.1, 9.4.0, 9.5.1, 10.2.3
Confluence Server - addressed in versions 9.2.1, 9.4.0, 9.5.1, 10.2.3
IBM Business Automation Manager Open Editions - update to 9.0.1
Bitbucket Data Center - addressed in versions 9.4.17, 10.1.5, 10.2.0
Bitbucket Server - addressed in versions 9.4.17, 10.1.5, 10.2.0
Event Streams - update to 11.3.0
IBM QRadar WinCollect Agent - update to 10.1.8
DevOps Test Performance - update to 11.0.8
Jira Service Management Data Center - update to 11.3.1
Jira Software Server - update to 11.3.2
Jira Software Data Center - update to 11.3.2
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-12
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-12, 2023.2.1-1
eap7 (Red Hat package) - addressed in versions mod_cluster-1.4.5-1.Final_redhat_00001.1.el7eap, mod_cluster-1.4.5-1.Final_redhat_00001.1.el8eap, mod_cluster-1.4.5-1.Final_redhat_00001.1.el9eap
Voice Gateway - addressed in versions 1.0.8.7, 1.0.8.11
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
IBM Security QRadar Network Threat Analytics - update to 1.4.0
Network Observability plugin for the Openshift Console - update to 1.4.0
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.7
eap7-ironjacamar (Red Hat package) - addressed in versions 1.5.15-1.Final_redhat_00001.1.el7eap, 1.5.15-1.Final_redhat_00001.1.el8eap, 1.5.15-1.Final_redhat_00001.1.el9eap
Netcool Operations Insight - update to 1.6.12
eap7-jboss-server-migration (Red Hat package) - addressed in versions 1.10.0-31.Final_redhat_00030.1.el7eap, 1.10.0-31.Final_redhat_00030.1.el8eap, 1.10.0-31.Final_redhat_00030.1.el9eap
eap7-jboss-modules (Red Hat package) - addressed in versions 1.12.2-1.Final_redhat_00001.1.el7eap, 1.12.2-1.Final_redhat_00001.1.el8eap, 1.12.2-1.Final_redhat_00001.1.el9eap
eap7-wildfly-elytron (Red Hat package) - addressed in versions 1.15.20-1.Final_redhat_00001.1.el7eap, 1.15.20-1.Final_redhat_00001.1.el8eap, 1.15.20-1.Final_redhat_00001.1.el9eap
yarnpkg - update to 1.22.22-5.el9
eap7-bouncycastle (Red Hat package) - addressed in versions 1.76.0-4.redhat_00001.1.el7eap, 1.76.0-4.redhat_00001.1.el8eap, 1.76.0-4.redhat_00001.1.el9eap
Storage Defender – Data Protect - update to 2.0.1
eap7-jboss-marshalling (Red Hat package) - addressed in versions 2.0.13-2.SP1_redhat_00001.1.el7eap, 2.0.13-2.SP1_redhat_00001.1.el8eap, 2.0.13-2.SP1_redhat_00001.1.el9eap
IBM Planning Analytics Workspace - update to 2.0.91
QRadar Pulse App - update to 2.2.11
eap7-undertow (Red Hat package) - addressed in versions 2.2.26-1.SP1_redhat_00001.1.el7eap, 2.2.26-1.SP1_redhat_00001.1.el8eap, 2.2.26-1.SP1_redhat_00001.1.el9eap
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
Cloud Pak for Network Automation - update to 2.6.1
IBM Fusion HCI - update to 2.7.0
eap7-activemq-artemis (Red Hat package) - addressed in versions 2.16.0-15.redhat_00049.1.el7eap, 2.16.0-15.redhat_00049.1.el8eap, 2.16.0-15.redhat_00049.1.el9eap
IBM Security QRadar Analyst Workflow - update to 2.32.0
nodejs-nodemon - addressed in versions 3.0.1-1, 3.0.1-1.0.1
QRadar Deployment Intelligence App - update to 3.0.12
eap7-hal-console (Red Hat package) - addressed in versions 3.3.19-1.Final_redhat_00001.1.el7eap, 3.3.19-1.Final_redhat_00001.1.el8eap, 3.3.19-1.Final_redhat_00001.1.el9eap
QRadar Assistant - update to 3.6.1
IBM Cloud Transformation Advisor - update to 3.7.0
eap7-jboss-xnio-base (Red Hat package) - addressed in versions 3.8.10-1.Final_redhat_00001.1.el7eap, 3.8.10-1.Final_redhat_00001.1.el8eap, 3.8.10-1.Final_redhat_00001.1.el9eap
IBM QRadar Use Case Manager - update to 3.9.0
eap7-resteasy (Red Hat package) - addressed in versions 3.15.8-1.Final_redhat_00001.1.el7eap, 3.15.8-1.Final_redhat_00001.1.el8eap, 3.15.8-1.Final_redhat_00001.1.el9eap
Red Hat OpenShift Dev Spaces - update to 3.24.0
QRadar User Behavior Analytics - update to 4.1.13
eap7-netty-transport-native-epoll (Red Hat package) - addressed in versions 4.1.94-1.Final_redhat_00001.1.el7eap, 4.1.94-1.Final_redhat_00001.1.el8eap, 4.1.94-1.Final_redhat_00001.1.el9eap
eap7-netty (Red Hat package) - addressed in versions 4.1.94-1.Final_redhat_00001.1.el7eap, 4.1.94-1.Final_redhat_00001.1.el8eap, 4.1.94-1.Final_redhat_00001.1.el9eap
Splunk Add-on for Google Cloud Platform - update to 4.3.0
IBM Cloud Pak for Watson AIOps - update to 4.4.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.3
IBM Decision Optimization for Cloud Pak for Data - update to 4.7.3
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.4
Watson AI Gateway for Cloud Pak for Data - update to 4.7.4
IBM DB2 - update to 4.8
Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
App Connect Enterprise Certified Container - addressed in versions 5.0.13, 11.0.0
IBM Storage Scale System - update to 5.1.2.13
eap7-hibernate (Red Hat package) - addressed in versions 5.3.31-1.Final_redhat_00001.1.el7eap, 5.3.31-1.Final_redhat_00001.1.el8eap, 5.3.31-1.Final_redhat_00001.1.el9eap
eap7-wildfly (Red Hat package) - addressed in versions 7.4.13-8.GA_redhat_00001.1.el7eap, 7.4.13-8.GA_redhat_00001.1.el8eap, 7.4.13-8.GA_redhat_00001.1.el9eap
IBM Maximo Application Suite - update to 8.10.5
npm - addressed in versions 8.19.4-1.16.20.2.2.0.2, 9.6.7-1.18.17.1.1.0.2
IBM DataPower Gateway - addressed in versions 10.0.1.15, 10.5.0.2, 10.5.0.7
IBM App Connect Enterprise - update to 11.0.0.22
nodejs-docs - addressed in versions 16.20.2-2.0.2, 18.17.1-1.0.2
nodejs-full-i18n - addressed in versions 16.20.2-2.0.2, 18.17.1-1.0.2
nodejs-devel - addressed in versions 16.20.2-2.0.2, 18.17.1-1.0.2
nodejs - addressed in versions 16.20.2-2.0.2, 18.17.1-1.0.2
nodejs - update to 18.12.1-1
Dell Data Protection Central - update to 19.10.0-4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.24, 23.0.1.2
IBM Automation Decision Services - update to 23.0.1 IF003
nodejs-packaging - addressed in versions 26-1.0.1, 2021.06-4
nodejs-packaging-bundler - update to 2021.06-4

External References

Related Security Bulletins