PT-2022-7028 · Oracle+2 · Oracle Fusion Middleware+5

Rbri

·

Published

2022-04-25

·

Updated

2023-12-07

·

CVE-2022-29546

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HtmlUnit NekoHtml Parser versions prior to 2.61.0 Oracle WebLogic Server (affected versions not specified) Oracle Fusion Middleware (affected versions not specified) Jira Service Management (affected versions not specified) Jira Work Management (affected versions not specified) Jira Software (affected versions not specified)
Description The issue is related to insufficient input validation in the NekoHTML component, which can lead to a denial of service (DoS) attack. Specifically, crafted input associated with the parsing of Processing Instruction (PI) data can cause heap memory consumption. This can allow a remote attacker to execute a DoS attack.
Recommendations For HtmlUnit NekoHtml Parser versions prior to 2.61.0, update to version 2.61.0. For Oracle WebLogic Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Oracle Fusion Middleware, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Jira Service Management, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Jira Work Management, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Jira Software, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-06979
CVE-2022-29546
GHSA-6JMM-MP6W-4RRG

Affected Products

Htmlunit Nekohtml Parser
Jira
Jira Service Management Server
Jira Work Management
Oracle Fusion Middleware
Oracle Weblogic Server