CVE-2022-42920Out-of-bounds Write in Software Foundation Apache Commons Bcel

CWE-787Out-of-bounds Write20 documents8 sources
Severity
9.8CRITICALNVD
EPSS
3.8%
top 11.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 7
Latest updateJan 16

Description

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDapache/commons_bcel< 6.6.0
CVEListV5apache_software_foundation/apache_commons_bcelApache Commons BCEL6.6.0
Debianapache/commons_bcel< 6.5.0-1+deb11u1+3
debiandebian/bcel< bcel 6.5.0-2 (bookworm)

Also affects: Fedora 35, 36, 37

🔴Vulnerability Details

3
OSV
CVE-2022-42920: Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics2022-11-07
OSV
Apache Commons BCEL vulnerable to out-of-bounds write2022-11-07
GHSA
Apache Commons BCEL vulnerable to out-of-bounds write2022-11-07

📋Vendor Advisories

8
Ubuntu
Apache Commons BCEL vulnerability2025-01-16
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache Commons BCEL) — CVE-2022-429202024-04-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Order and Service Management (Apache Commons BCEL) — CVE-2022-429202024-01-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Print Preview (Apache Commons BCEL) — CVE-2022-429202023-10-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Commons BCEL) — CVE-2022-429202023-07-15

🕵️Threat Intelligence

8
Qualys
Oracle Security Updates, April 2024: Critical Patch | Qualys2024-04-17
Qualys
Oracle Patch Update, April 2024 Security Update Review2024-04-17
Qualys
Oracle Patch Update, January 2024 Security Update Review2024-01-17
Qualys
Oracle Patch Update, January 2024 Security Update Review | Qualys2024-01-17
Qualys
Oracle Patch Tuesday, October 2023 Security Update Review | Qualys2023-10-18
CVE-2022-42920 — Out-of-bounds Write | cvebase