CVE-2022-45685
published 2022-12-13CVE-2022-45685: A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.40%
69.7th percentile
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | jira_software | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libjettison-java | < libjettison-java 1.5.3-1 (bookworm) | libjettison-java 1.5.3-1 (bookworm) |
| jettison_project | jettison | < 1.5.2 | 1.5.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59/8.60 Security denial of service (Nessus ID 309923)
vuldb·2026-04-24·CVSS 7.5
CVE-2022-45685 [HIGH] Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59/8.60 Security denial of service (Nessus ID 309923)
A vulnerability described as critical has been identified in Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59/8.60. This impacts an unknown function of the component Security. The manipulation results in denial of service.
This vulnerability is identified as CVE-2022-45685. The attack can be executed remotely. There is not any exploit available.
VulDB
Oracle WebLogic Server 12.2.1.3.0/12.2.1.4.0/14.1.1.0.0 Third Party denial of service (Nessus ID 309923)
vuldb·2026-04-24·CVSS 7.5
CVE-2022-45685 [HIGH] Oracle WebLogic Server 12.2.1.3.0/12.2.1.4.0/14.1.1.0.0 Third Party denial of service (Nessus ID 309923)
A vulnerability, which was classified as critical, was found in Oracle WebLogic Server 12.2.1.3.0/12.2.1.4.0/14.1.1.0.0. Impacted is an unknown function of the component Third Party. Such manipulation leads to denial of service.
This vulnerability is referenced as CVE-2022-45685. It is possible to launch the attack remotely. No exploit is available.
VulDB
Jettison up to 1.5.1 JSON Data stack-based overflow (Issue 54 / Nessus ID 309923)
vuldb·2026-04-24·CVSS 7.5
CVE-2022-45685 [HIGH] Jettison up to 1.5.1 JSON Data stack-based overflow (Issue 54 / Nessus ID 309923)
A vulnerability identified as critical has been detected in Jettison up to 1.5.1. Affected by this issue is some unknown functionality of the component JSON Data Handler. This manipulation causes stack-based buffer overflow.
This vulnerability appears as CVE-2022-45685. The attacker needs to be present on the local network. There is no available exploit.
You should upgrade the affected component.
OSV
CVE-2022-45685: A stack overflow in Jettison before v1
osv·2022-12-13·CVSS 7.5
CVE-2022-45685 [HIGH] CVE-2022-45685: A stack overflow in Jettison before v1
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
OSV
Jettison Out-of-bounds Write vulnerability
osv·2022-12-13
CVE-2022-45685 [HIGH] Jettison Out-of-bounds Write vulnerability
Jettison Out-of-bounds Write vulnerability
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
GHSA
Jettison Out-of-bounds Write vulnerability
ghsa·2022-12-13
CVE-2022-45685 [HIGH] CWE-787 Jettison Out-of-bounds Write vulnerability
Jettison Out-of-bounds Write vulnerability
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
Atlassian
CVE-2022-45685: DoS (Denial of Service) org.codehaus.jettison:jettison Dependency in Jira Software Data Center and Server
vendor_atlassian·2024-03-19·CVSS 7.5
CVE-2022-45685 [HIGH] CVE-2022-45685: DoS (Denial of Service) org.codehaus.jettison:jettison Dependency in Jira Software Data Center and Server
CVE-2022-45685: DoS (Denial of Service) org.codehaus.jettison:jettison Dependency in Jira Software Data Center and Server
DoS (Denial of Service) org.codehaus.jettison:jettison Dependency in Jira Software Data Center and Server
CVE: CVE-2022-45685
Affected products: Jira Software
Ubuntu
Jettison vulnerabilities
vendor_ubuntu·2023-06-19
CVE-2022-45685 Jettison vulnerabilities
Title: Jettison vulnerabilities
Summary: Several security issues were fixed in Jettison.
It was discovered that Jettison incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Jettison) — CVE-2022-45685
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-45685 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Jettison) — CVE-2022-45685
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Jettison) vulnerability
CVE: CVE-2022-45685
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Red Hat
jettison: stack overflow in JSONObject() allows attackers to cause a Denial of Service (DoS) via crafted JSON data
vendor_redhat·2022-12-23·CVSS 7.5
CVE-2022-45685 [HIGH] CWE-787 jettison: stack overflow in JSONObject() allows attackers to cause a Denial of Service (DoS) via crafted JSON data
jettison: stack overflow in JSONObject() allows attackers to cause a Denial of Service (DoS) via crafted JSON data
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
A flaw was found in Jettison. Sending a specially crafted string can cause a stack-based buffer overflow. This issue may allow a remote attacker to cause a denial of service.
Statement: Red Hat has determined the impact of this flaw to be Moderate. A successful attack using this flaw would require the processing of untrusted, unsanitized, or unrestricted user inputs, which runs counter to established Red Hat security practices.
Package: jettison (A-MQ Clients 2) - Not affected
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat O
Debian
CVE-2022-45685: libjettison-java - A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of...
vendor_debian·2022·CVSS 7.5
CVE-2022-45685 [HIGH] CVE-2022-45685: libjettison-java - A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of...
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
Scope: local
bookworm: resolved (fixed in 1.5.3-1)
bullseye: resolved (fixed in 1.5.3-1~deb11u1)
forky: resolved (fixed in 1.5.3-1)
sid: resolved (fixed in 1.5.3-1)
trixie: resolved (fixed in 1.5.3-1)
No detection rules found.
No public exploits indexed.
https://github.com/jettison-json/jettison/issues/54https://lists.debian.org/debian-lts-announce/2022/12/msg00045.htmlhttps://www.debian.org/security/2023/dsa-5312https://github.com/jettison-json/jettison/issues/54https://lists.debian.org/debian-lts-announce/2022/12/msg00045.htmlhttps://www.debian.org/security/2023/dsa-5312
2022-12-13
Published