Bug 2107994 (CVE-2022-2458)

Summary: CVE-2022-2458 Business-central: Possible XML External Entity Injection attack
Product: [Other] Security Response Reporter: Paramvir jindal <pjindal>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: alazarot, anstephe, emingora, ibek, jrokos, kverlaen, mnovotny, pjindal, rguimara, rrajasek
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
An XML external entity injection(XXE) vulnerability was found in Business Central. This flaw allows an attacker to interfere with an application's processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. Here, the XML external entity injection leads to External Service interaction and an Internal file read in Business Central and Kie-Server APIs.
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-11-29 09:28:02 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2107984    

Description Paramvir jindal 2022-07-18 08:22:59 UTC
IBM pentesting results :
https://docs.google.com/spreadsheets/d/1Iwbhk0lwGoNskLidsY5CXmc5MwKt5VfmJCaX21xyruo


XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with
an application's processing of XML data. This attack occurs when XML input containing a
reference to an external entity is processed by a weakly configured XML parser.
The software processes an XML document that can contain XML entities with URIs that
resolve to documents outside of the intended sphere of control, causing the product to
embed incorrect documents into its output.
Here, XML external entity injection lead to External Service interaction & Internal file read in
Business Central and also Kie-Server APIs.

Comment 5 errata-xmlrpc 2022-10-05 10:46:42 UTC
This issue has been addressed in the following products:

  RHPAM 7.13.1 async

Via RHSA-2022:6813 https://access.redhat.com/errata/RHSA-2022:6813

Comment 8 Product Security DevOps Team 2022-11-29 09:28:00 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-2458