PT-2022-7028 · Oracle+2 · Oracle Fusion Middleware+5
Rbri
·
Published
2022-04-25
·
Updated
2023-12-07
·
CVE-2022-29546
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
HtmlUnit NekoHtml Parser versions prior to 2.61.0
Oracle WebLogic Server (affected versions not specified)
Oracle Fusion Middleware (affected versions not specified)
Jira Service Management (affected versions not specified)
Jira Work Management (affected versions not specified)
Jira Software (affected versions not specified)
Description
The issue is related to insufficient input validation in the NekoHTML component, which can lead to a denial of service (DoS) attack. Specifically, crafted input associated with the parsing of Processing Instruction (PI) data can cause heap memory consumption. This can allow a remote attacker to execute a DoS attack.
Recommendations
For HtmlUnit NekoHtml Parser versions prior to 2.61.0, update to version 2.61.0.
For Oracle WebLogic Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Oracle Fusion Middleware, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Jira Service Management, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Jira Work Management, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Jira Software, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Htmlunit Nekohtml Parser
Jira
Jira Service Management Server
Jira Work Management
Oracle Fusion Middleware
Oracle Weblogic Server