CVE-2022-23221Argument Injection in Oracle Communications Cloud Native Core Console

Severity
9.8CRITICALNVD
EPSS
26.6%
top 3.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 19
Latest updateJun 13

Description

H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDh2database/h21.1.1002.0.206
debiandebian/h2database< h2database 2.1.210-1 (bookworm)

Also affects: Debian Linux 10.0, 11.0, 9.0

Patches

🔴Vulnerability Details

4
OSV
h2database vulnerabilities2022-04-05
OSV
Arbitrary code execution in H2 Console2022-01-21
GHSA
Arbitrary code execution in H2 Console2022-01-21
OSV
CVE-2022-23221: H2 Console before 22022-01-19

📋Vendor Advisories

7
Ubuntu
H2 vulnerabilities2024-06-13
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: B2B Engine (H2 Database) — CVE-2022-232212024-01-15
Oracle
Oracle Oracle HealthCare Applications Risk Matrix: Data Studio (H2 Database) — CVE-2022-232212023-01-15
Oracle
Oracle Oracle Communications Risk Matrix: CNC Console (H2) — CVE-2022-232212022-04-15
Ubuntu
H2 vulnerabilities2022-04-05

🕵️Threat Intelligence

2
Qualys
Oracle Patch Update, January 2024 Security Update Review2024-01-17
Qualys
Oracle Patch Update, January 2024 Security Update Review | Qualys2024-01-17
CVE-2022-23221 — Argument Injection in Oracle | cvebase