SQL injection in Postgresql JDBC Driver - CVE-2022-31197
Published: August 24, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data within the java.sql.ResultRow.refreshRow() method when processing column names. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database using the statement terminator, e.g." ;".
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Affected software
Analytics Content Hub
IBM Security Verify Information Queue
InfoSphere Data Replication
Dell EMC PowerStore Family Operating System
IBM Data Risk Manager
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
openEuler
Fedora
SecureTransport
IBM Tivoli Netcool Impact
Bitbucket Data Center
IBM Security Verify Governance
Oracle Enterprise Data Quality
Netcool Operations Insight
Red Hat build of Quarkus
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Observability with Instana
Fuse
Bitbucket Server
Zoho ManageEngine OpManager
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Cloud Foundry UAA
IBM Disconnected Log Collector
watsonx.data
postgresql-jdbc
postgresql-jdbc (Red Hat package)
postgresql-jdbc-javadoc
postgresql-jdbc-help
How to mitigate CVE-2022-31197
Analytics Content Hub - update to 2.2
IBM Data Risk Manager - update to 2.0.6.15
SecureTransport - update to 5.5-20220825
IBM Tivoli Netcool Impact - update to 7.1.0.27
Fuse - update to 7.11.1
Bitbucket Data Center - addressed in versions 8.9.25, 8.19.15, 9.4.3, 9.5.1
Bitbucket Server - addressed in versions 8.9.25, 8.19.15, 9.4.3, 9.5.1
IBM Security Verify Governance - update to 10.0.1.0.3
IBM Security Verify Information Queue - update to 10.0.5
Zoho ManageEngine OpManager - update to 12.6 126147
Cloud Foundry UAA - update to 75.23.0
Netcool Operations Insight - update to 1.6.8
IBM Disconnected Log Collector - update to 1.8.3
Cloud Pak for Security (CP4S) - update to 1.10.10.0
watsonx.data - update to 2.0.2
Red Hat build of Quarkus - update to 2.7.7
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.0
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
postgresql-jdbc - addressed in versions 9.4-3.6.3, 42.2.10-150200.3.11.1, 42.2.25-150300.3.8.1, 42.2.25-150400.3.6.1
postgresql-jdbc (Red Hat package) - update to 42.2.18-6.el9_1
postgresql-jdbc-javadoc - addressed in versions 42.2.25-150300.3.8.1, 42.2.25-150400.3.6.1
postgresql-jdbc - addressed in versions 42.2.26-1.fc35, 42.3.1-4.fc36
postgresql-jdbc-help - update to 42.4.1-1
postgresql-jdbc-javadoc - update to 42.4.1-1
postgresql-jdbc - update to 42.4.1-1
IBM Observability with Instana - update to 265
External References
Related Security Bulletins
- SQL injection in Postgresql JDBC driver
- SQL injection in Cloud Foundry UAA
- Zoho ManageEngine OpManager update for PostgreSQL and PostgreSQL JDBC Driver
- SQL injection in IBM Tivoli Netcool Impact
- SUSE update for postgresql-jdbc
- SUSE update for postgresql-jdbc
- SUSE update for postgresql-jdbc
- SUSE update for postgresql-jdbc
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in IBM Data Risk Manager
- SQL injection in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- IBM Security Verify Governance update for PostgreSQL
- Red Hat Enterprise Linux 9 update for postgresql-jdbc
- Multiple vulnerabilities in Red Hat build of Quarkus
- Multiple vulnerabilities in Axway SecureTransport (August 2022)
- Multiple vulnerabilities in IBM Security Verify Information Queue
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Oracle Enterprise Data Quality
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM InfoSphere Data Replication
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in IBM Disconnected Log Collector
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- openEuler update for postgresql-jdbc
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in IBM Analytics Content Hub
- Multiple vulnerabilities in IBM watsonx.data
- Fedora 35 update for postgresql-jdbc
- Fedora 36 update for postgresql-jdbc
- Bitbucket Data Center and Server update for postgresql