Input validation error in dicer - CVE-2022-24434

 

Input validation error in dicer - CVE-2022-24434

Published: July 4, 2022


Vulnerability identifier: #VU64874
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24434
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a modified form to server, and crash the nodejs service. An attacker can sent the payload again and again so that the service continuously crashes.


Affected software

dicer
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Netcool Operations Insight
Spectrum Discover
UCV – UrbanCode Velocity
Cloud Pak for Data
IBM Edge Application Manager
IBM Planning Analytics Workspace
IBM Cloud Pak for Watson AIOps
IBM QRadar Use Case Manager
IBM Cognos Analytics

How to mitigate CVE-2022-24434

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6
Cloud Pak for Data - update to 4.8.5
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-8, 2022.2.1-1
Netcool Operations Insight - update to 1.6.7
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
IBM Planning Analytics Workspace - update to 2.0.91
UCV – UrbanCode Velocity - update to 3.1.3
IBM Cloud Pak for Watson AIOps - update to 3.4.2
IBM QRadar Use Case Manager - update to 3.6.0
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4.1 IF1

External References

Related Security Bulletins