CVE-2022-42920
published 2022-11-07CVE-2022-42920: Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing…
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.84%
85.1th percentile
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | commons_bcel | < 6.6.0 | 6.6.0 |
| apache | commons_bcel | >= 0 < 6.5.0-1+deb11u1 | 6.5.0-1+deb11u1 |
| apache | commons_bcel | >= 0 < 6.5.0-2 | 6.5.0-2 |
| apache | commons_bcel | >= 0 < 6.5.0-2 | 6.5.0-2 |
| apache | commons_bcel | >= 0 < 6.5.0-2 | 6.5.0-2 |
| apache_software_foundation | apache_commons_bcel | >= Apache Commons BCEL < 6.6.0 | 6.6.0 |
| debian | bcel | < bcel 6.5.0-2 (bookworm) | bcel 6.5.0-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-42920: Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics
osv·2022-11-07·CVSS 9.8
CVE-2022-42920 [CRITICAL] CVE-2022-42920: Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.
OSV
Apache Commons BCEL vulnerable to out-of-bounds write
osv·2022-11-07
CVE-2022-42920 [CRITICAL] Apache Commons BCEL vulnerable to out-of-bounds write
Apache Commons BCEL vulnerable to out-of-bounds write
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.
GHSA
Apache Commons BCEL vulnerable to out-of-bounds write
ghsa·2022-11-07
CVE-2022-42920 [CRITICAL] CWE-787 Apache Commons BCEL vulnerable to out-of-bounds write
Apache Commons BCEL vulnerable to out-of-bounds write
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.
Ubuntu
Apache Commons BCEL vulnerability
vendor_ubuntu·2025-01-16
CVE-2022-42920 Apache Commons BCEL vulnerability
Title: Apache Commons BCEL vulnerability
Summary: Apache Commons BCEL could be made to crash or run programs
if it received specially crafted network traffic.
Felix Wilhelm discovered that Apache Commons BCEL APIs
incorrectly handled parameters due to a memory issue. An
attacker supplying malicious input could exploit this to
generate and execute arbitrary bytecode.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache Commons BCEL) — CVE-2022-42920
vendor_oracle·2024-04-15·CVSS 9.8
CVE-2022-42920 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache Commons BCEL) — CVE-2022-42920
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache Commons BCEL) vulnerability
CVE: CVE-2022-42920
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Order and Service Management (Apache Commons BCEL) — CVE-2022-42920
vendor_oracle·2024-01-15·CVSS 9.8
CVE-2022-42920 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Order and Service Management (Apache Commons BCEL) — CVE-2022-42920
Oracle Oracle Communications Applications Risk Matrix: Order and Service Management (Apache Commons BCEL) vulnerability
CVE: CVE-2022-42920
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Print Preview (Apache Commons BCEL) — CVE-2022-42920
vendor_oracle·2023-10-15·CVSS 9.8
CVE-2022-42920 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Print Preview (Apache Commons BCEL) — CVE-2022-42920
Oracle Oracle Communications Applications Risk Matrix: Print Preview (Apache Commons BCEL) vulnerability
CVE: CVE-2022-42920
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Commons BCEL) — CVE-2022-42920
vendor_oracle·2023-07-15·CVSS 9.8
CVE-2022-42920 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Commons BCEL) — CVE-2022-42920
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Commons BCEL) vulnerability
CVE: CVE-2022-42920
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Third party Jars (Apache Commons BCEL) — CVE-2022-42920
vendor_oracle·2023-01-15·CVSS 9.8
CVE-2022-42920 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Third party Jars (Apache Commons BCEL) — CVE-2022-42920
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Third party Jars (Apache Commons BCEL) vulnerability
CVE: CVE-2022-42920
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Red Hat
Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing
vendor_redhat·2022-11-04·CVSS 9.8
CVE-2022-42920 [CRITICAL] CWE-787 Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing
Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.
An out-of-bounds (OOB) write flaw was found in Apache Commons BCEL API. This flaw can be used to produce arbitrary bytecode and may abuse applications that pass attacker-controlled data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected.
Statemen
Debian
CVE-2022-42920: bcel - Apache Commons BCEL has a number of APIs that would normally only allow changing...
vendor_debian·2022·CVSS 9.8
CVE-2022-42920 [CRITICAL] CVE-2022-42920: bcel - Apache Commons BCEL has a number of APIs that would normally only allow changing...
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.
Scope: local
bookworm: resolved (fixed in 6.5.0-2)
bullseye: resolved (fixed in 6.5.0-1+deb11u1)
forky: resolved (fixed in 6.5.0-2)
sid: resolved (fixed in 6.5.0-2)
trixie: resolved (fixed in 6.5.0-2)
No detection rules found.
No public exploits indexed.
Qualys
Oracle Security Updates, April 2024: Critical Patch | Qualys
blogs_qualys·2024-04-17
Oracle Security Updates, April 2024: Critical Patch | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle released its second quarterly edition of Critical Patch Update, which contains patches for 441 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In the second quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 93, constituting about 21% of the total patches released. Oracle Fusion Middleware and Oracle Financial Services Applicat
Qualys
Oracle Patch Update, April 2024 Security Update Review
blogs_qualys·2024-04-17
Oracle Patch Update, April 2024 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle released its second quarterly edition of Critical Patch Update, which contains patches for 441 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In the second quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 93, constituting about 21% of the total patches released. Oracle Fusion Middleware and Oracle Financial Services Applications fo
Qualys
Oracle Patch Update, January 2024 Security Update Review
blogs_qualys·2024-01-17
Oracle Patch Update, January 2024 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Oracle has released its first quarterly edition of Critical Patch Update, which contains patches for 389 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in a wide range of product families, including Oracle code and third-party components included in Oracle products.
In the first quarterly Oracle Critical Patch Update, Oracle Financial Services Applications received the highest number of patches, 71, constituting 18% of the total patches released. Oracle Communications and Oracle Communications Applications follow
Qualys
Oracle Patch Update, January 2024 Security Update Review | Qualys
blogs_qualys·2024-01-17
Oracle Patch Update, January 2024 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Oracle has released its first quarterly edition of Critical Patch Update, which contains patches for 389 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in a wide range of product families, including Oracle code and third-party components included in Oracle products.
In the first quarterly Oracle Critical Patch Update, Oracle Financial Services Applications received the highest number of patches, 71, constituting 18% of the total patches released. Oracle Communications and Oracle Communications Applications
Qualys
Oracle Patch Tuesday, October 2023 Security Update Review | Qualys
blogs_qualys·2023-10-18
Oracle Patch Tuesday, October 2023 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released its fourth quarterly edition of Critical Patch Update, which contains a group of patches for 387 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During the Q4 2023 Oracle Critical Patch Update, Oracle Financial Services Applications received the highest number of 103 patches, constituting 26% of the total patches released. Oracle Communications and Oracle Fusion Middleware fo
Qualys
Oracle Patch Tuesday, October 2023 Security Update Review
blogs_qualys·2023-10-18
Oracle Patch Tuesday, October 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released its fourth quarterly edition of Critical Patch Update, which contains a group of patches for 387 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During the Q4 2023 Oracle Critical Patch Update, Oracle Financial Services Applications received the highest number of 103 patches, constituting 26% of the total patches released. Oracle Communications and Oracle Fusion Middleware followed,
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followed, with
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followe
http://www.openwall.com/lists/oss-security/2022/11/07/2https://lists.apache.org/thread/lfxk7q8qmnh5bt9jm6nmjlv5hsxjhrz4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LX3HEB4TV2BVCGDTK5BCLSYOZNQTOBN4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QAMRHAKGIKZNHRBB4VLYTOIOIMMXCUCD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMVX6COVXZVS5GPWDODIRW6Z2GE7RPAQ/https://security.gentoo.org/glsa/202401-25http://www.openwall.com/lists/oss-security/2022/11/07/2https://lists.apache.org/thread/lfxk7q8qmnh5bt9jm6nmjlv5hsxjhrz4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LX3HEB4TV2BVCGDTK5BCLSYOZNQTOBN4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QAMRHAKGIKZNHRBB4VLYTOIOIMMXCUCD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMVX6COVXZVS5GPWDODIRW6Z2GE7RPAQ/https://security.gentoo.org/glsa/202401-25
2022-11-07
Published