SQL injection in Postgresql JDBC Driver - CVE-2022-31197

 

SQL injection in Postgresql JDBC Driver - CVE-2022-31197

Published: August 24, 2022


Vulnerability identifier: #VU66747
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31197
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data within the java.sql.ResultRow.refreshRow() method when processing column names. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database using the statement terminator, e.g." ;".

Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.


Affected software

Postgresql JDBC Driver
Analytics Content Hub
IBM Security Verify Information Queue
InfoSphere Data Replication
Dell EMC PowerStore Family Operating System
IBM Data Risk Manager
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
openEuler
Fedora
SecureTransport
IBM Tivoli Netcool Impact
Bitbucket Data Center
IBM Security Verify Governance
Oracle Enterprise Data Quality
Netcool Operations Insight
Red Hat build of Quarkus
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Observability with Instana
Fuse
Bitbucket Server
Zoho ManageEngine OpManager
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Cloud Foundry UAA
IBM Disconnected Log Collector
watsonx.data
postgresql-jdbc
postgresql-jdbc (Red Hat package)
postgresql-jdbc-javadoc
postgresql-jdbc-help

How to mitigate CVE-2022-31197

Install update from vendor's website.

Postgresql JDBC Driver - addressed in versions 42.2.26, 42.4.1
Analytics Content Hub - update to 2.2
IBM Data Risk Manager - update to 2.0.6.15
SecureTransport - update to 5.5-20220825
IBM Tivoli Netcool Impact - update to 7.1.0.27
Fuse - update to 7.11.1
Bitbucket Data Center - addressed in versions 8.9.25, 8.19.15, 9.4.3, 9.5.1
Bitbucket Server - addressed in versions 8.9.25, 8.19.15, 9.4.3, 9.5.1
IBM Security Verify Governance - update to 10.0.1.0.3
IBM Security Verify Information Queue - update to 10.0.5
Zoho ManageEngine OpManager - update to 12.6 126147
Cloud Foundry UAA - update to 75.23.0
Netcool Operations Insight - update to 1.6.8
IBM Disconnected Log Collector - update to 1.8.3
Cloud Pak for Security (CP4S) - update to 1.10.10.0
watsonx.data - update to 2.0.2
Red Hat build of Quarkus - update to 2.7.7
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.0
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
postgresql-jdbc - addressed in versions 9.4-3.6.3, 42.2.10-150200.3.11.1, 42.2.25-150300.3.8.1, 42.2.25-150400.3.6.1
postgresql-jdbc (Red Hat package) - update to 42.2.18-6.el9_1
postgresql-jdbc-javadoc - addressed in versions 42.2.25-150300.3.8.1, 42.2.25-150400.3.6.1
postgresql-jdbc - addressed in versions 42.2.26-1.fc35, 42.3.1-4.fc36
postgresql-jdbc-help - update to 42.4.1-1
postgresql-jdbc-javadoc - update to 42.4.1-1
postgresql-jdbc - update to 42.4.1-1
IBM Observability with Instana - update to 265

External References

Related Security Bulletins