PT-2022-27413 · Apache+1 · Apache Jena Tdb 2+2
Crilwa
+1
·
Published
2022-11-14
·
Updated
2024-08-03
·
CVE-2022-45136
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Jena SDB versions 3.17.0 and earlier
Description
The issue allows for a JDBC Deserialisation attack if the attacker can control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver is known to be vulnerable to this class of attack. As a result, an application using Apache Jena SDB can be subject to RCE when connected to a malicious database server. Apache Jena SDB has been EOL since December 2020.
Recommendations
To resolve the issue, users should migrate to alternative options, such as Apache Jena TDB 2.
As a temporary workaround, consider restricting access to the vulnerable JDBC URL until a patch is available.
Avoid using the mySQL JDBC driver in Apache Jena SDB until the issue is resolved.
Migrate to Apache Jena TDB 2 to minimize the risk of exploitation.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Jena Sdb
Apache Jena Tdb 2
Mysql Jdbc Driver