PT-2023-1972 · Apache+6 · Apache Openoffice+7
Published
2023-03-24
·
Updated
2025-02-13
·
CVE-2022-38745
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache OpenOffice versions before 4.1.14
Description
The issue is related to the possibility of adding an empty entry to the Java class path in Apache OpenOffice. This could allow a remote attacker to execute arbitrary Java code from the current directory by loading a specially crafted java file.
Recommendations
For versions before 4.1.14, update to version 4.1.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the Java class path to minimize the risk of exploitation.
Exploit
Fix
Uncontrolled Search Path Element
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Apache Openoffice
Astra Linux
Centos
Linuxmint
Openoffice
Red Hat
Ubuntu