CVE-2022-40150
published 2022-09-16CVE-2022-40150: Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.30%
67.7th percentile
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect may support a denial of service attack.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | jira_software | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libjettison-java | < libjettison-java 1.5.3-1 (bookworm) | libjettison-java 1.5.3-1 (bookworm) |
| jettison | jettison | unspecified – 1.4.0 | — |
| jettison_project | jettison | <= 1.4.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_oracle7.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Analytics Risk Matrix: BI Platform Security (Jettison) — CVE-2022-40150
vendor_oracle·2025-01-15·CVSS 7.5
CVE-2022-40150 [MEDIUM] Oracle Oracle Analytics Risk Matrix: BI Platform Security (Jettison) — CVE-2022-40150
Oracle Oracle Analytics Risk Matrix: BI Platform Security (Jettison) vulnerability
CVE: CVE-2022-40150
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Atlassian
CVE-2022-40150: 9.12.0 to 9.12.2 LTS 9.11.0 to 9.11.3 9.10.0 to 9.10.2 9.9.0 to 9.9.2 9.8.0 to 9.8.2 9.7.0 to 9.7.2 9.6.0 9.5.0 to 9.5.1
vendor_atlassian·2024-03-19·CVSS 9.1
CVE-2022-40150 [MEDIUM] CVE-2022-40150: 9.12.0 to 9.12.2 LTS 9.11.0 to 9.11.3 9.10.0 to 9.10.2 9.9.0 to 9.9.2 9.8.0 to 9.8.2 9.7.0 to 9.7.2 9.6.0 9.5.0 to 9.5.1
CVE-2022-40150: 9.12.0 to 9.12.2 LTS 9.11.0 to 9.11.3 9.10.0 to 9.10.2 9.9.0 to 9.9.2 9.8.0 to 9.8.2 9.7.0 to 9.7.2 9.6.0 9.5.0 to 9.5.1
9.12.0 to 9.12.2 LTS 9.11.0 to 9.11.3 9.10.0 to 9.10.2 9.9.0 to 9.9.2 9.8.0 to 9.8.2 9.7.0 to 9.7.2 9.6.0 9.5.0 to 9.5.1 9.4.0 to 9.4.17 LTS 9.3.0 to 9.3.3 9.2.0 to 9.2.1 9.1.0 to 9.1.1 9.0.0 Any earlier versions
CVE: CVE-2022-40150
Affected products: Jira Software
Oracle
Oracle Oracle Siebel CRM Risk Matrix: EAI (Jettison) — CVE-2022-40150
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2022-40150 [MEDIUM] Oracle Oracle Siebel CRM Risk Matrix: EAI (Jettison) — CVE-2022-40150
Oracle Oracle Siebel CRM Risk Matrix: EAI (Jettison) vulnerability
CVE: CVE-2022-40150
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Ubuntu
Jettison vulnerabilities
vendor_ubuntu·2023-06-19
CVE-2022-45685 Jettison vulnerabilities
Title: Jettison vulnerabilities
Summary: Several security issues were fixed in Jettison.
It was discovered that Jettison incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Webservices Manager (Jettison) — CVE-2022-40150
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2022-40150 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Webservices Manager (Jettison) — CVE-2022-40150
Oracle Oracle Communications Applications Risk Matrix: Webservices Manager (Jettison) vulnerability
CVE: CVE-2022-40150
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Red Hat
jettison: memory exhaustion via user-supplied XML or JSON data
vendor_redhat·2022-09-20·CVSS 6.5
CVE-2022-40150 [MEDIUM] CWE-400 jettison: memory exhaustion via user-supplied XML or JSON data
jettison: memory exhaustion via user-supplied XML or JSON data
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect may support a denial of service attack.
A vulnerability was found in Jettison, where parsing an untrusted XML or JSON data may lead to a crash. If the parser is running on user-supplied input, an attacker may supply content that causes the parser to crash, causing memory exhaustion. This effect may support a denial of service attack.
Package: jettison (A-MQ Clients 2) - Not affected
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Fi
Debian
CVE-2022-40150: libjettison-java - Those using Jettison to parse untrusted XML or JSON data may be vulnerable to De...
vendor_debian·2022·CVSS 6.5
CVE-2022-40150 [MEDIUM] CVE-2022-40150: libjettison-java - Those using Jettison to parse untrusted XML or JSON data may be vulnerable to De...
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect may support a denial of service attack.
Scope: local
bookworm: resolved (fixed in 1.5.3-1)
bullseye: resolved (fixed in 1.5.3-1~deb11u1)
forky: resolved (fixed in 1.5.3-1)
sid: resolved (fixed in 1.5.3-1)
trixie: resolved (fixed in 1.5.3-1)
OSV
Jettison memory exhaustion
osv·2022-09-17
CVE-2022-40150 [HIGH] Jettison memory exhaustion
Jettison memory exhaustion
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect may support a denial of service attack.
GHSA
Jettison memory exhaustion
ghsa·2022-09-17
CVE-2022-40150 [HIGH] CWE-400 Jettison memory exhaustion
Jettison memory exhaustion
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect may support a denial of service attack.
OSV
CVE-2022-40150: Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS)
osv·2022-09-16·CVSS 7.5
CVE-2022-40150 [HIGH] CVE-2022-40150: Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS)
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect may support a denial of service attack.
No detection rules found.
No public exploits indexed.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46549https://github.com/jettison-json/jettison/issues/45https://lists.debian.org/debian-lts-announce/2022/12/msg00045.htmlhttps://www.debian.org/security/2023/dsa-5312https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46549https://github.com/jettison-json/jettison/issues/45https://lists.debian.org/debian-lts-announce/2022/12/msg00045.htmlhttps://www.debian.org/security/2023/dsa-5312
2022-09-16
Published