CVE-2022-45693
published 2022-12-13CVE-2022-45693: Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS)…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.40%
69.7th percentile
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libjettison-java | < libjettison-java 1.5.3-1 (bookworm) | libjettison-java 1.5.3-1 (bookworm) |
| jettison_project | jettison | < 1.5.2 | 1.5.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security (Jettison) — CVE-2022-45693
vendor_oracle·2025-07-15·CVSS 7.5
CVE-2022-45693 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Security (Jettison) — CVE-2022-45693
Oracle Oracle Fusion Middleware Risk Matrix: Security (Jettison) vulnerability
CVE: CVE-2022-45693
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Jettison) — CVE-2022-45693
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2022-45693 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Jettison) — CVE-2022-45693
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Jettison) vulnerability
CVE: CVE-2022-45693
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Ubuntu
Jettison vulnerabilities
vendor_ubuntu·2023-06-19
CVE-2022-45685 Jettison vulnerabilities
Title: Jettison vulnerabilities
Summary: Several security issues were fixed in Jettison.
It was discovered that Jettison incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Jettison) — CVE-2022-45693
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-45693 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Jettison) — CVE-2022-45693
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Jettison) vulnerability
CVE: CVE-2022-45693
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Red Hat
jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos
vendor_redhat·2022-12-13·CVSS 7.5
CVE-2022-45693 [HIGH] CWE-787 jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos
jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
A flaw was found in Jettison, where it is vulnerable to a denial of service caused by a stack-based buffer overflow. By sending a specially-crafted request using the map parameter, a remote attacker can cause a denial of service.
Statement: Red Hat has determined the impact of this flaw to be Moderate; a successful attack using this flaw would require the processing of untrusted, unsanitized, or unrestricted user inputs, which runs counter to established Red Hat security practices.
Pac
Debian
CVE-2022-45693: libjettison-java - Jettison before v1.5.2 was discovered to contain a stack overflow via the map pa...
vendor_debian·2022·CVSS 7.5
CVE-2022-45693 [HIGH] CVE-2022-45693: libjettison-java - Jettison before v1.5.2 was discovered to contain a stack overflow via the map pa...
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
Scope: local
bookworm: resolved (fixed in 1.5.3-1)
bullseye: resolved (fixed in 1.5.3-1~deb11u1)
forky: resolved (fixed in 1.5.3-1)
sid: resolved (fixed in 1.5.3-1)
trixie: resolved (fixed in 1.5.3-1)
OSV
CVE-2022-45693: Jettison before v1
osv·2022-12-13·CVSS 7.5
CVE-2022-45693 [HIGH] CVE-2022-45693: Jettison before v1
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
OSV
Jettison Out-of-bounds Write vulnerability
osv·2022-12-13
CVE-2022-45693 [HIGH] Jettison Out-of-bounds Write vulnerability
Jettison Out-of-bounds Write vulnerability
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
GHSA
Jettison Out-of-bounds Write vulnerability
ghsa·2022-12-13
CVE-2022-45693 [HIGH] CWE-787 Jettison Out-of-bounds Write vulnerability
Jettison Out-of-bounds Write vulnerability
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
No detection rules found.
No public exploits indexed.
https://github.com/jettison-json/jettison/issues/52https://lists.debian.org/debian-lts-announce/2022/12/msg00045.htmlhttps://www.debian.org/security/2023/dsa-5312https://github.com/jettison-json/jettison/issues/52https://lists.debian.org/debian-lts-announce/2022/12/msg00045.htmlhttps://www.debian.org/security/2023/dsa-5312
2022-12-13
Published