PT-2022-27413 · Apache+1 · Apache Jena Tdb 2+2

Crilwa

+1

·

Published

2022-11-14

·

Updated

2024-08-03

·

CVE-2022-45136

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Jena SDB versions 3.17.0 and earlier
Description The issue allows for a JDBC Deserialisation attack if the attacker can control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver is known to be vulnerable to this class of attack. As a result, an application using Apache Jena SDB can be subject to RCE when connected to a malicious database server. Apache Jena SDB has been EOL since December 2020.
Recommendations To resolve the issue, users should migrate to alternative options, such as Apache Jena TDB 2. As a temporary workaround, consider restricting access to the vulnerable JDBC URL until a patch is available. Avoid using the mySQL JDBC driver in Apache Jena SDB until the issue is resolved. Migrate to Apache Jena TDB 2 to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2022-45136
GHSA-G2QW-6VRR-V6PQ

Affected Products

Apache Jena Sdb
Apache Jena Tdb 2
Mysql Jdbc Driver