Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-46337 @ Maven-org.apache.derby:derby-10.13.1.1 #115

Open
SamHeadrickCx opened this issue Jun 19, 2024 · 0 comments
Open

CVE-2022-46337 @ Maven-org.apache.derby:derby-10.13.1.1 #115

SamHeadrickCx opened this issue Jun 19, 2024 · 0 comments

Comments

@SamHeadrickCx
Copy link
Owner

Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about CVE-2022-46337
Checkmarx Project: SamHeadrickCx/easybuggy4sb
Repository URL: https://github.com/SamHeadrickCx/easybuggy4sb
Branch: master
Scan ID: 94cbf8fd-fbe8-49c7-9c55-da0658f9cbfc


A cleverly devised username might bypass LDAP authentication checks in versions prior to 10.14.3, 10.15.0.x prior to 10.15.2.1, 10.16.0.x prior to 10.16.1.2, and 10.17.0.x prior to 10.17.1.0. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby installations, this could also allow the attacker to execute malware which was visible to and executable by the account which booted the Derby server. In LDAP-protected databases which weren't also protected by SQL GRANT/REVOKE authorization, this vulnerability could also let an attacker view and corrupt sensitive data and run sensitive database functions and procedures. Alternatively, users who wish to remain on older Java versions should build their own Derby distribution from one of the release families to which the fix was backported. Those are the releases which correspond, respectively, with Java LTS versions 17, 11, and 8.


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: HIGH
Availability impact: HIGH
Remediation Upgrade Recommendation: 10.17.1.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant