LDAP injection in Apache Derby - CVE-2022-46337

 

LDAP injection in Apache Derby - CVE-2022-46337

Published: November 28, 2023


Vulnerability identifier: #VU83545
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46337
CWE-ID: CWE-90
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to improper input validation when processing DLAP queries. A remote non-authenticated attacker can send a specially crafted LDAP query to the application, bypass authentication process and gain unauthorized access to the application.


Affected software

Apache Derby
IBM Operations Analytics Predictive Insights
IBM Transformation Extender Advanced
IBM Integration Bus
Oracle Middleware Common Libraries and Tools
Oracle Enterprise Data Quality
Jazz for Service Management
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM TXSeries for Multiplatforms
IBM Business Automation Workflow
IBM Cloud Pak for Multicloud Management
IBM Cloud Pak System
DB2 Data Management Console
webMethods BPM
Oracle FLEXCUBE Private Banking
Oracle Application Testing Suite
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
IBM Engineering Lifecycle Optimization - Publishing
Oracle Solaris Cluster
IBM Qradar SIEM
Dell Data Lakehouse
Jazz Reporting Service
Juniper Secure Analytics (JSA)
IBM CICS TX Advanced
IBM App Connect Enterprise
IBM CICS TX Standard
Oracle Commerce Guided Search
Oracle Fusion Middleware MapViewer
Oracle Documaker
Operational Decision Manager
Oracle Retail Integration Bus
watsonx.data

How to mitigate CVE-2022-46337

Install updates from vendor's website.

Apache Derby - update to 10.17.1.0
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Cloud Pak System - addressed in versions 2.3.3.6 iFix 2, 2.3.3.7 iFix 01
DB2 Data Management Console - update to 3.1.13
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF06
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF06
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix32, 11.1.0.0 ifix24
IBM App Connect Enterprise - addressed in versions 11.0.0.24, 12.0.11.1
webMethods BPM - update to 11.1 Fix 2
IBM CICS TX Standard - update to 11.1.0.0 ifix25
Jazz for Service Management - update to 1.1.3.21
Dell Data Lakehouse - update to 1.4.0.0
Netcool Operations Insight - update to 1.6.12
watsonx.data - update to 2.0.2
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
IBM Spectrum Control - update to 5.4.11
Jazz Reporting Service - addressed in versions 7.0.2 iFix033, 7.0.3 iFix0012
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.2.32, 7.0.3.10
IBM Tivoli Netcool Impact - update to 7.1.0.33
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.22
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10
IBM TXSeries for Multiplatforms - addressed in versions 9.1.0.3, 10.1.0.0
IBM Business Automation Workflow - addressed in versions 21.0.3 IF030, 23.0.2 IF002

External References

Related Security Bulletins