Incorrect Regular Expression in Semver - CVE-2022-25883
Published: August 3, 2023 / Updated: November 30, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing regular expressions. A remote attacker can pass specially crafted data to the application via the new Range function and perform regular expression denial of service (ReDos) attack.
Affected software
IBM Cloud Pak for Security
IBM Observability with Instana
Migration Toolkit for Runtimes
IBM Process Mining
OpenShift Logging
Confluence Data Center
Bitbucket Data Center
IBM QRadar WinCollect Agent
Jira Service Management Data Center
Jira Software Data Center
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Netcool Operations Insight
IBM Fusion HCI
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
QRadar User Behavior Analytics
Splunk Add-on for Google Cloud Platform
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
Oracle Linux
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Fedora
Security QRadar Offenses Forwarder
DB2 Data Management Console
Storage Fusion Data Foundation
IBM Business Automation Manager Open Editions
Rational Performance Tester
DevOps Test Performance
Business Automation Insights
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
IBM Security QRadar Network Threat Analytics
IBM i Modernization Engine for Lifecycle Integration
Storage Defender – Data Protect
IBM Planning Analytics Workspace
Cloud Pak for Network Automation
QRadar Deployment Intelligence App
QRadar Assistant
IBM Cloud Pak for Watson AIOps
Watson AI Gateway for Cloud Pak for Data
Dell Data Protection Central
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
IBM Edge Application Manager
IBM DataPower Gateway
QRadar Suite
Juniper Secure Analytics (JSA)
IBM Security QRadar Analyst Workflow
Splunk Add-on Builder
Network Observability plugin for the Openshift Console
Splunk Enterprise Security (ES)
IBM Cloud Pak System
JBoss Enterprise Application Platform
Bitbucket Server
Confluence Server
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
eap7 (Red Hat package)
eap7-ironjacamar (Red Hat package)
eap7-jboss-server-migration (Red Hat package)
eap7-jboss-modules (Red Hat package)
eap7-wildfly-elytron (Red Hat package)
yarnpkg
eap7-bouncycastle (Red Hat package)
eap7-jboss-marshalling (Red Hat package)
eap7-undertow (Red Hat package)
eap7-activemq-artemis (Red Hat package)
nodejs-nodemon
eap7-hal-console (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
eap7-resteasy (Red Hat package)
eap7-netty-transport-native-epoll (Red Hat package)
eap7-netty (Red Hat package)
eap7-hibernate (Red Hat package)
eap7-wildfly (Red Hat package)
npm
nodejs-docs
nodejs-full-i18n
nodejs-devel
nodejs
nodejs-packaging
nodejs-packaging-bundler
Event Streams
Jira Software Server
Cloud Pak for Data
IBM InfoSphere Information Server
IBM DB2
Voice Gateway
QRadar Pulse App
IBM QRadar Use Case Manager
IBM Storage Scale System
IBM App Connect Enterprise
How to mitigate CVE-2022-25883
Security QRadar Offenses Forwarder - update to 1.2.0
Migration Toolkit for Runtimes - update to 1.2.4
Migration Toolkit for Containers - update to 1.8.2
QRadar Suite - update to 1.10.19.0
IBM Process Mining - update to 1.14.2
IBM Cloud Pak for Multicloud Management - update to 2.3.8
DB2 Data Management Console - update to 3.1.13.2
Splunk Add-on Builder - update to 4.1.4
Splunk Enterprise Security (ES) - addressed in versions 7.1.2, 7.2.0, 7.3.0
OpenShift Logging - update to 5.7.4
JBoss Enterprise Application Platform - update to 7.4.13
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04
Confluence Data Center - addressed in versions 9.2.1, 9.4.0, 9.5.1, 10.2.3
Confluence Server - addressed in versions 9.2.1, 9.4.0, 9.5.1, 10.2.3
IBM Business Automation Manager Open Editions - update to 9.0.1
Bitbucket Data Center - addressed in versions 9.4.17, 10.1.5, 10.2.0
Bitbucket Server - addressed in versions 9.4.17, 10.1.5, 10.2.0
Event Streams - update to 11.3.0
IBM QRadar WinCollect Agent - update to 10.1.8
DevOps Test Performance - update to 11.0.8
Jira Service Management Data Center - update to 11.3.1
Jira Software Server - update to 11.3.2
Jira Software Data Center - update to 11.3.2
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-12
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-12, 2023.2.1-1
eap7 (Red Hat package) - addressed in versions mod_cluster-1.4.5-1.Final_redhat_00001.1.el7eap, mod_cluster-1.4.5-1.Final_redhat_00001.1.el8eap, mod_cluster-1.4.5-1.Final_redhat_00001.1.el9eap
Voice Gateway - addressed in versions 1.0.8.7, 1.0.8.11
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
IBM Security QRadar Network Threat Analytics - update to 1.4.0
Network Observability plugin for the Openshift Console - update to 1.4.0
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.7
eap7-ironjacamar (Red Hat package) - addressed in versions 1.5.15-1.Final_redhat_00001.1.el7eap, 1.5.15-1.Final_redhat_00001.1.el8eap, 1.5.15-1.Final_redhat_00001.1.el9eap
Netcool Operations Insight - update to 1.6.12
eap7-jboss-server-migration (Red Hat package) - addressed in versions 1.10.0-31.Final_redhat_00030.1.el7eap, 1.10.0-31.Final_redhat_00030.1.el8eap, 1.10.0-31.Final_redhat_00030.1.el9eap
eap7-jboss-modules (Red Hat package) - addressed in versions 1.12.2-1.Final_redhat_00001.1.el7eap, 1.12.2-1.Final_redhat_00001.1.el8eap, 1.12.2-1.Final_redhat_00001.1.el9eap
eap7-wildfly-elytron (Red Hat package) - addressed in versions 1.15.20-1.Final_redhat_00001.1.el7eap, 1.15.20-1.Final_redhat_00001.1.el8eap, 1.15.20-1.Final_redhat_00001.1.el9eap
yarnpkg - update to 1.22.22-5.el9
eap7-bouncycastle (Red Hat package) - addressed in versions 1.76.0-4.redhat_00001.1.el7eap, 1.76.0-4.redhat_00001.1.el8eap, 1.76.0-4.redhat_00001.1.el9eap
Storage Defender – Data Protect - update to 2.0.1
eap7-jboss-marshalling (Red Hat package) - addressed in versions 2.0.13-2.SP1_redhat_00001.1.el7eap, 2.0.13-2.SP1_redhat_00001.1.el8eap, 2.0.13-2.SP1_redhat_00001.1.el9eap
IBM Planning Analytics Workspace - update to 2.0.91
QRadar Pulse App - update to 2.2.11
eap7-undertow (Red Hat package) - addressed in versions 2.2.26-1.SP1_redhat_00001.1.el7eap, 2.2.26-1.SP1_redhat_00001.1.el8eap, 2.2.26-1.SP1_redhat_00001.1.el9eap
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
Cloud Pak for Network Automation - update to 2.6.1
IBM Fusion HCI - update to 2.7.0
eap7-activemq-artemis (Red Hat package) - addressed in versions 2.16.0-15.redhat_00049.1.el7eap, 2.16.0-15.redhat_00049.1.el8eap, 2.16.0-15.redhat_00049.1.el9eap
IBM Security QRadar Analyst Workflow - update to 2.32.0
nodejs-nodemon - addressed in versions 3.0.1-1, 3.0.1-1.0.1
QRadar Deployment Intelligence App - update to 3.0.12
eap7-hal-console (Red Hat package) - addressed in versions 3.3.19-1.Final_redhat_00001.1.el7eap, 3.3.19-1.Final_redhat_00001.1.el8eap, 3.3.19-1.Final_redhat_00001.1.el9eap
QRadar Assistant - update to 3.6.1
IBM Cloud Transformation Advisor - update to 3.7.0
eap7-jboss-xnio-base (Red Hat package) - addressed in versions 3.8.10-1.Final_redhat_00001.1.el7eap, 3.8.10-1.Final_redhat_00001.1.el8eap, 3.8.10-1.Final_redhat_00001.1.el9eap
IBM QRadar Use Case Manager - update to 3.9.0
eap7-resteasy (Red Hat package) - addressed in versions 3.15.8-1.Final_redhat_00001.1.el7eap, 3.15.8-1.Final_redhat_00001.1.el8eap, 3.15.8-1.Final_redhat_00001.1.el9eap
Red Hat OpenShift Dev Spaces - update to 3.24.0
QRadar User Behavior Analytics - update to 4.1.13
eap7-netty-transport-native-epoll (Red Hat package) - addressed in versions 4.1.94-1.Final_redhat_00001.1.el7eap, 4.1.94-1.Final_redhat_00001.1.el8eap, 4.1.94-1.Final_redhat_00001.1.el9eap
eap7-netty (Red Hat package) - addressed in versions 4.1.94-1.Final_redhat_00001.1.el7eap, 4.1.94-1.Final_redhat_00001.1.el8eap, 4.1.94-1.Final_redhat_00001.1.el9eap
Splunk Add-on for Google Cloud Platform - update to 4.3.0
IBM Cloud Pak for Watson AIOps - update to 4.4.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.3
IBM Decision Optimization for Cloud Pak for Data - update to 4.7.3
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.4
Watson AI Gateway for Cloud Pak for Data - update to 4.7.4
IBM DB2 - update to 4.8
Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
App Connect Enterprise Certified Container - addressed in versions 5.0.13, 11.0.0
IBM Storage Scale System - update to 5.1.2.13
eap7-hibernate (Red Hat package) - addressed in versions 5.3.31-1.Final_redhat_00001.1.el7eap, 5.3.31-1.Final_redhat_00001.1.el8eap, 5.3.31-1.Final_redhat_00001.1.el9eap
eap7-wildfly (Red Hat package) - addressed in versions 7.4.13-8.GA_redhat_00001.1.el7eap, 7.4.13-8.GA_redhat_00001.1.el8eap, 7.4.13-8.GA_redhat_00001.1.el9eap
IBM Maximo Application Suite - update to 8.10.5
npm - addressed in versions 8.19.4-1.16.20.2.2.0.2, 9.6.7-1.18.17.1.1.0.2
IBM DataPower Gateway - addressed in versions 10.0.1.15, 10.5.0.2, 10.5.0.7
IBM App Connect Enterprise - update to 11.0.0.22
nodejs-docs - addressed in versions 16.20.2-2.0.2, 18.17.1-1.0.2
nodejs-full-i18n - addressed in versions 16.20.2-2.0.2, 18.17.1-1.0.2
nodejs-devel - addressed in versions 16.20.2-2.0.2, 18.17.1-1.0.2
nodejs - addressed in versions 16.20.2-2.0.2, 18.17.1-1.0.2
nodejs - update to 18.12.1-1
Dell Data Protection Central - update to 19.10.0-4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.24, 23.0.1.2
IBM Automation Decision Services - update to 23.0.1 IF003
nodejs-packaging - addressed in versions 26-1.0.1, 2021.06-4
nodejs-packaging-bundler - update to 2021.06-4
External References
- https://github.com/npm/node-semver/commit/717534ee353682f3bcf33e60a8af4292626d4441
- https://github.com/npm/node-semver/blob/main/internal/re.js%23L138
- https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795
- https://github.com/npm/node-semver/blob/main/internal/re.js%23L160
- https://github.com/npm/node-semver/blob/main/classes/range.js%23L97-L104
- https://github.com/npm/node-semver/pull/564
Related Security Bulletins
- Regular expression denial of service in semver
- Multiple vulnerabilities in Red Hat OpenShift Logging 5.7
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Multiple vulnerabilities in IBM QRadar Pulse App
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Incorrect regular expression in IBM Storage Scale
- Red Hat Enterprise Linux 9 update for the nodejs:18 module
- Red Hat Enterprise Linux 8 update for the nodejs:18 module
- Red Hat Enterprise Linux 8.6 Extended Update Support update for the nodejs:16 module
- Red Hat Enterprise Linux 8 update for the nodejs:16 module
- Multiple vulnerabilities in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Network Observability for OpenShift
- Incorrect regular expression in IBM Process Mining
- Multiple vulnerabilities in IBM DataPower Gateway
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- Multiple vulnerabilities in JBoss Enterprise Application Platform 7.4 for RHEL 8
- Multiple vulnerabilities in JBoss Enterprise Application Platform 7.4 for RHEL 7
- Multiple vulnerabilities in JBoss Enterprise Application Platform 7.4 for RHEL 9
- Incorrect regular expression in IBM Decision Optimization for Cloud Pak for Data
- Incorrect regular expression in IBM Maximo Application Suite - Monitor Component
- Incorrect regular expression in Platform Navigator and Automation Assets in IBM Cloud Pak for Integration
- Multiple vulnerabilities in IBM Storage Fusion
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Splunk Add-on for Google Cloud Platform
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- IBM InfoSphere Information Server update for Node.js semver
- IBM Event Streams update for Node.js
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- IBM Watson Assistant for IBM Cloud Pak for Data update for Node.js semver
- IBM Watson AI Gateway for IBM Cloud Pak for Data update for Node.js semver package
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- App Connect Enterprise Certified Container update for Node.js semver package
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- IBM Cloud Pak System update for Node.js Semver
- Multiple vulnerabilities in IBM Analyst Workflow
- Splunk Enterprise Security (ES) update for third-party components
- Multiple vulnerabilities in IBM QRadar Deployment Intelligence App
- Dell Data Protection Central update for third-party components
- Splunk Add-on Builder update for third-party components
- Juniper Networks Juniper Secure Analytics update for third-party applications
- Multiple vulnerabilities in IBM QRadar Assistant
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in IBM QRadar Use Case Manager
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM i Modernization Engine for Lifecycle Integration
- Incorrect regular expression in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Security QRadar Offenses Forwarder
- Fedora EPEL 9 update for yarnpkg
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (Android)
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (iOS)
- Amazon Linux AMI update for nodejs
- Anolis OS update for nodejs:16 module
- Anolis OS update for nodejs:18 module
- Multiple vulnerabilities in IBM Knowledge Catalog for IBM Cloud Pak for Data
- IBM Storage Fusion Data Foundation update for package semver
- Multiple vulnerabilities in IBM Security QRadar Network Threat Analytics
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in IBM Business Automation Insights
- Jira Service Management Data Center update for Semver
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Confluence Data Center and Server update for Semver
- Jira Software Data Center and Server update for Semver
- Bitbucket Data Center and Server update for Semver
- IBM DevOps Test Performance update for package semver