Bug 2107994 (CVE-2022-2458) - CVE-2022-2458 Business-central: Possible XML External Entity Injection attack
Summary: CVE-2022-2458 Business-central: Possible XML External Entity Injection attack
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2022-2458
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2107984
TreeView+ depends on / blocked
 
Reported: 2022-07-18 08:22 UTC by Paramvir jindal
Modified: 2022-11-29 09:28 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
An XML external entity injection(XXE) vulnerability was found in Business Central. This flaw allows an attacker to interfere with an application's processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. Here, the XML external entity injection leads to External Service interaction and an Internal file read in Business Central and Kie-Server APIs.
Clone Of:
Environment:
Last Closed: 2022-11-29 09:28:02 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2022:6813 0 None None None 2022-10-05 10:46:45 UTC

Description Paramvir jindal 2022-07-18 08:22:59 UTC
IBM pentesting results :
https://docs.google.com/spreadsheets/d/1Iwbhk0lwGoNskLidsY5CXmc5MwKt5VfmJCaX21xyruo


XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with
an application's processing of XML data. This attack occurs when XML input containing a
reference to an external entity is processed by a weakly configured XML parser.
The software processes an XML document that can contain XML entities with URIs that
resolve to documents outside of the intended sphere of control, causing the product to
embed incorrect documents into its output.
Here, XML external entity injection lead to External Service interaction & Internal file read in
Business Central and also Kie-Server APIs.

Comment 5 errata-xmlrpc 2022-10-05 10:46:42 UTC
This issue has been addressed in the following products:

  RHPAM 7.13.1 async

Via RHSA-2022:6813 https://access.redhat.com/errata/RHSA-2022:6813

Comment 8 Product Security DevOps Team 2022-11-29 09:28:00 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-2458


Note You need to log in before you can comment on or make changes to this bug.