XML External Entity injection in Apache Ivy - CVE-2022-46751

 

XML External Entity injection in Apache Ivy - CVE-2022-46751

Published: August 21, 2023


Vulnerability identifier: #VU79749
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46751
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.


Affected software

Apache Ivy
Red Hat Camel for Spring Boot
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
Ivy
IvyTrigger
Migration Toolkit for Runtimes
IBM Operations Analytics Predictive Insights
Oracle Communications Cloud Native Core Automated Test Suite
Netcool Operations Insight
QRadar User Behavior Analytics
IBM Watson Assistant for IBM Cloud Pak for Data
Red Hat Migration Toolkit for Applications
UCD - IBM UrbanCode Deploy
IBM Spectrum Protect Plus
AMQ Streams
IBM Cloud Pak for Watson AIOps
Oracle Business Intelligence Enterprise Edition
User Entity Behavior Analytics
apache-ivy
apache-ivy-javadoc
IBM Cloud Pak System

How to mitigate CVE-2022-46751

Install updates from vendor's website.

Apache Ivy - update to 2.5.2
IvyTrigger - update to 1.02
Migration Toolkit for Runtimes - update to 1.2.4
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
AMQ Streams - update to 2.6.0
Netcool Operations Insight - update to 1.6.11
apache-ivy - addressed in versions 2.2.0-5.2, 2.5.1-1
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
apache-ivy-javadoc - update to 2.5.2-150200.3.9.1
apache-ivy - update to 2.5.2-150200.3.9.1
Red Hat Camel for Spring Boot - update to 4.0.0
QRadar User Behavior Analytics - update to 4.1.16
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.4
User Entity Behavior Analytics - update to 5.0.2
Red Hat Migration Toolkit for Applications - update to 6.2
UCD - IBM UrbanCode Deploy - addressed in versions 7.0.5.18, 7.1.2.14, 7.2.3.7, 7.3.2.2
IBM Spectrum Protect Plus - update to 10.1.6.4

External References

Related Security Bulletins