XML External Entity injection in Apache Ivy - CVE-2022-46751
Published: August 21, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
Affected software
Red Hat Camel for Spring Boot
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
Ivy
IvyTrigger
Migration Toolkit for Runtimes
IBM Operations Analytics Predictive Insights
Oracle Communications Cloud Native Core Automated Test Suite
Netcool Operations Insight
QRadar User Behavior Analytics
IBM Watson Assistant for IBM Cloud Pak for Data
Red Hat Migration Toolkit for Applications
UCD - IBM UrbanCode Deploy
IBM Spectrum Protect Plus
AMQ Streams
IBM Cloud Pak for Watson AIOps
Oracle Business Intelligence Enterprise Edition
User Entity Behavior Analytics
apache-ivy
apache-ivy-javadoc
IBM Cloud Pak System
How to mitigate CVE-2022-46751
IvyTrigger - update to 1.02
Migration Toolkit for Runtimes - update to 1.2.4
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
AMQ Streams - update to 2.6.0
Netcool Operations Insight - update to 1.6.11
apache-ivy - addressed in versions 2.2.0-5.2, 2.5.1-1
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
apache-ivy-javadoc - update to 2.5.2-150200.3.9.1
apache-ivy - update to 2.5.2-150200.3.9.1
Red Hat Camel for Spring Boot - update to 4.0.0
QRadar User Behavior Analytics - update to 4.1.16
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.4
User Entity Behavior Analytics - update to 5.0.2
Red Hat Migration Toolkit for Applications - update to 6.2
UCD - IBM UrbanCode Deploy - addressed in versions 7.0.5.18, 7.1.2.14, 7.2.3.7, 7.3.2.2
IBM Spectrum Protect Plus - update to 10.1.6.4
External References
- https://docs.oracle.com/en/java/javase/13/security/java-api-xml-processing-jaxp-security-guide.html#GUID-94ABC0EE-9DC8-44F0-84AD-47ADD5340477
- https://gitbox.apache.org/repos/asf?p=ant-ivy.git;a=commit;h=2be17bc18b0e1d4123007d579e43ba1a4b6fab3d
- https://lists.apache.org/thread/9gcz4xrsn8c7o9gb377xfzvkb8jltffr
- https://ant.apache.org/
- https://www.cve.org/CVERecord?id=CVE-2022-46751
Related Security Bulletins
- XXE in Apache Ivy
- Multiple vulnerabilities in Jenkins Ivy plugin
- Multiple vulnerabilities in Red Hat Integration Camel for Spring Boot 4.0
- Amazon Linux AMI update for apache-ivy
- SUSE update for apache-ivy
- XML external entity injection in IBM UrbanCode Deploy (UCD)
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat AMQ Streams
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Automated Test Suite
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Two vulnerabilities in Red Hat Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in IBM Operations Analytics Predictive Insights
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- XML External Entity injection in Jenkins IvyTrigger plugin
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Amazon Linux AMI update for apache-ivy
- Multiple vulnerabilities in IBM User Entity Behavior Analytics