CVE-2022-43859
published 2022-12-22CVE-2022-43859: IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.58%
43.6th percentile
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | i | — | — |
| ibm | i | — | — |
| ibm | i | — | — |
| ibm | navigator_for_i | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
ghsa7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ppqf-24vq-48jf: IBM Navigator for i 7
ghsa_unreviewed·2022-12-22
CVE-2022-43859 [MEDIUM] CWE-89 GHSA-ppqf-24vq-48jf: IBM Navigator for i 7
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.
GHSA
DoS vulnerability in bundled XStream library in Jenkins Core
ghsa·2022-02-10·CVSS 7.5
CVE-2022-0538 [HIGH] CWE-502 DoS vulnerability in bundled XStream library in Jenkins Core
DoS vulnerability in bundled XStream library in Jenkins Core
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier is affected by the XStream library’s vulnerability [CVE-2021-43859](https://x-stream.github.io/CVE-2021-43859.html). This library is used by Jenkins to serialize and deserialize various XML files, like global and job `config.xml`, `build.xml`, and numerous others.
This allows attackers able to submit crafted XML files to Jenkins to be parsed as configuration, e.g. through the `POST config.xml` API, to cause a denial of service (DoS).
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (XStream) — CVE-2021-43859
vendor_oracle·2022-10-15·CVSS 7.5
CVE-2021-43859 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: General (XStream) — CVE-2021-43859
Oracle Oracle Fusion Middleware Risk Matrix: General (XStream) vulnerability
CVE: CVE-2021-43859
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: EM Gateway (XStream) — CVE-2021-43859
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2021-43859 [HIGH] Oracle Oracle Communications Applications Risk Matrix: EM Gateway (XStream) — CVE-2021-43859
Oracle Oracle Communications Applications Risk Matrix: EM Gateway (XStream) vulnerability
CVE: CVE-2021-43859
CVSS: 7.5
Protocol: TCP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Visualization, Database (XStream) — CVE-2021-43859
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2021-43859 [HIGH] Oracle Oracle Communications Risk Matrix: Visualization, Database (XStream) — CVE-2021-43859
Oracle Oracle Communications Risk Matrix: Visualization, Database (XStream) vulnerability
CVE: CVE-2021-43859
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
jenkins: DoS vulnerability in bundled XStream library
vendor_redhat·2022-02-09·CVSS 7.5
CVE-2022-0538 [HIGH] CWE-502 jenkins: DoS vulnerability in bundled XStream library
jenkins: DoS vulnerability in bundled XStream library
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.
A denial of service (DoS) flaw was found in Jenkins. This flaw allows an attacker to define custom XStream converters that do not protect against the vulnerability in CVE-2021-43859, allowing for uncontrolled resource consumption.
Package: jenkins (Red Hat Fuse 7) - Not affected
Package: jenkins (Red Hat OpenShift Container Platform 3.11) - Not affected
Package: jenkins (Red Hat OpenShift Container Platform 4) - Not affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-22
Published