CVE-2022-25147
published 2023-01-31CVE-2022-25147: Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of…
PriorityP434medium6.5CVSS 3.1
AVNACLPRNUINSUCNILAL
EPSS
1.42%
69.8th percentile
Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer.
This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apr-util | >= 0 < 1.6.3-r0 | 1.6.3-r0 |
| apache | apr-util | >= 0 < 1.6.3-r0 | 1.6.3-r0 |
| apache | apr-util | >= 0 < 1.6.3-r0 | 1.6.3-r0 |
| apache | apr-util | >= 0 < 1.6.3-r0 | 1.6.3-r0 |
| apache | apr-util | >= 0 < 1.6.3-r0 | 1.6.3-r0 |
| apache | apr-util | >= 0 < 1.6.3-r0 | 1.6.3-r0 |
| apache | apr-util | >= 0 < 1.6.3-r0 | 1.6.3-r0 |
| apache | apr-util | >= 0 < 1.6.3-r0 | 1.6.3-r0 |
| apache | apr-util | >= 0 < 1.6.3-r0 | 1.6.3-r0 |
| apache | apr-util | >= 0 < 1.6.3-r0 | 1.6.3-r0 |
| apache | apr-util | >= 0 < 1.6.1-5+deb11u1 | 1.6.1-5+deb11u1 |
| apache | apr-util | >= 0 < 1.6.3-1 | 1.6.3-1 |
| apache | apr-util | >= 0 < 1.6.3-1 | 1.6.3-1 |
| apache | apr-util | >= 0 < 1.6.3-1 | 1.6.3-1 |
| apache | portable_runtime_utility | <= 1.6.1 | — |
| apache_software_foundation | apache_portable_runtime_utility | <= 1.6.1 | — |
| debian | apr-util | < apr-util 1.6.3-1 (bookworm) | apr-util 1.6.3-1 (bookworm) |
| msrc | cbl2_apr-util_1.6.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_apr-util_1.6.3-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
ABB M2M Gateway
cisa_ics·2025-04-15
ABB M2M Gateway
ICS Advisory
##
ABB M2M Gateway
Release DateApril 15, 2025
Alert CodeICSA-25-105-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: M2M Gateway
- Vulnerabilities: Integer Overflow or Wraparound, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Unquoted Search Path or Element, Untrusted Search Path, Use After Free, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Missing Release of Memory after Effective Lifetime, Allocation of Resources Without Limits or Throttling, Improper Privilege Management, Improper Limitati
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache Portable Runtime Utility) — CVE-2022-25147
vendor_oracle·2024-04-15·CVSS 6.5
CVE-2022-25147 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache Portable Runtime Utility) — CVE-2022-25147
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache Portable Runtime Utility) vulnerability
CVE: CVE-2022-25147
CVSS: 6.5
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Application (Apache Portable Runtime Utility) — CVE-2022-25147
vendor_oracle·2024-01-15·CVSS 6.5
CVE-2022-25147 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Application (Apache Portable Runtime Utility) — CVE-2022-25147
Oracle Oracle Financial Services Applications Risk Matrix: Application (Apache Portable Runtime Utility) vulnerability
CVE: CVE-2022-25147
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Apache Portable Runtime Utility) — CVE-2022-25147
vendor_oracle·2023-10-15·CVSS 6.5
CVE-2022-25147 [MEDIUM] Oracle Oracle Communications Risk Matrix: Platform (Apache Portable Runtime Utility) — CVE-2022-25147
Oracle Oracle Communications Risk Matrix: Platform (Apache Portable Runtime Utility) vulnerability
CVE: CVE-2022-25147
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Virtual Network Function Manager (Apache Portable Runtime Utility) — CVE-2022-25147
vendor_oracle·2023-07-15·CVSS 6.5
CVE-2022-25147 [MEDIUM] Oracle Oracle Communications Risk Matrix: Virtual Network Function Manager (Apache Portable Runtime Utility) — CVE-2022-25147
Oracle Oracle Communications Risk Matrix: Virtual Network Function Manager (Apache Portable Runtime Utility) vulnerability
CVE: CVE-2022-25147
CVSS: 6.5
Protocol: LDAP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Ubuntu
apr-util vulnerability
vendor_ubuntu·2023-02-14
CVE-2022-25147 apr-util vulnerability
Title: apr-util vulnerability
Summary: APR-util could be made to crash or run programs as an administrator
if it received specially crafted input.
Ronald Crane discovered that APR-util did not properly handled memory when
encoding or decoding certain input data. An attacker could possibly use
this issue to cause a denial of service, or possibly execute arbitrary
code.
Instructions: After a standard system update you need to restart any application
using APR-util libraries to make all the necessary changes.
Red Hat
apr-util: out-of-bounds writes in the apr_base64
vendor_redhat·2023-01-31·CVSS 6.5
CVE-2022-25147 [MEDIUM] CWE-190 apr-util: out-of-bounds writes in the apr_base64
apr-util: out-of-bounds writes in the apr_base64
Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer.
This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.
A flaw was found in the Apache Portable Runtime Utility (APR-util) library. This issue may allow a malicious attacker to cause an out-of-bounds write due to an integer overflow when encoding/decoding a very long string using the base64 family of functions.
Statement: The Apache Portable Runtime Utility (APR-util) library contains additional utility interfaces for APR (Apache Portable Runtime).
This vulnerability is related to the incorrect usage of the base64 encoding/decoding family o
Microsoft
Apache Portable Runtime Utility (APR-util): out-of-bounds writes in the apr_base64 family of functions
vendor_msrc·2023-01-10·CVSS 6.5
CVE-2022-25147 [MEDIUM] CWE-190 Apache Portable Runtime Utility (APR-util): out-of-bounds writes in the apr_base64 family of functions
Apache Portable Runtime Utility (APR-util): out-of-bounds writes in the apr_base64 family of functions
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediatio
Debian
CVE-2022-25147: apr-util - Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache P...
vendor_debian·2022·CVSS 6.5
CVE-2022-25147 [MEDIUM] CVE-2022-25147: apr-util - Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache P...
Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.
Scope: local
bookworm: resolved (fixed in 1.6.3-1)
bullseye: resolved (fixed in 1.6.1-5+deb11u1)
forky: resolved (fixed in 1.6.3-1)
sid: resolved (fixed in 1.6.3-1)
trixie: resolved (fixed in 1.6.3-1)
GHSA
GHSA-37mv-q3x5-3mwg: Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond
ghsa_unreviewed·2023-01-31
CVE-2022-25147 [CRITICAL] CWE-190 GHSA-37mv-q3x5-3mwg: Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond
Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.
OSV
CVE-2022-25147: Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond
osv·2023-01-31·CVSS 6.5
CVE-2022-25147 [MEDIUM] CVE-2022-25147: Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond
Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.
OSV
CVE-2022-25147: Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond
osv·2023-01-31·CVSS 6.5
CVE-2022-25147 [MEDIUM] CVE-2022-25147: Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond
Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer.
This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-31
Published