CVE-2022-32287

CWE-22Path Traversal6 documents5 sources
Severity
7.5HIGH
EPSS
0.8%
top 26.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 3

Description

A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. This issue affects Apache UIMA Apache UIMA version 3.3.0 and prior versions. Note that PEAR files should never be installed into an UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the sam

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDapache/uimaj3.3.0
CVEListV5apache_software_foundation/apache_uimaJava SDK3.3.0

🔴Vulnerability Details

4
OSV
Apache UIMA Path Traversal vulnerability2022-11-03
CVEList
Apache UIMA prior to 3.3.1 has a path traversal vulnerability when extracting (PEAR) archives2022-11-03
OSV
CVE-2022-32287: A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files ou2022-11-03
GHSA
Apache UIMA Path Traversal vulnerability2022-11-03

📋Vendor Advisories

1
Red Hat
uima: path traversal during archive extraction2022-11-03
CVE-2022-32287 (HIGH CVSS 7.5) | A relative path traversal vulnerabi | cvebase.io