PT-2023-1972 · Apache+6 · Apache Openoffice+7

Published

2023-03-24

·

Updated

2025-02-13

·

CVE-2022-38745

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache OpenOffice versions before 4.1.14
Description The issue is related to the possibility of adding an empty entry to the Java class path in Apache OpenOffice. This could allow a remote attacker to execute arbitrary Java code from the current directory by loading a specially crafted java file.
Recommendations For versions before 4.1.14, update to version 4.1.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the Java class path to minimize the risk of exploitation.

Exploit

Fix

Uncontrolled Search Path Element

Code Injection

Weakness Enumeration

Related Identifiers

ALSA-2023:6508
ALSA-2023:6933
BDU:2023-01592
CESA-2023_6933
CVE-2022-38745
DLA-3526-1
RHSA-2023:6508
RHSA-2023:6933
RHSA-2023_6508
RHSA-2023_6933
USN-6023-1

Affected Products

Almalinux
Apache Openoffice
Astra Linux
Centos
Linuxmint
Openoffice
Red Hat
Ubuntu