CVE-2022-41853
Summary
| CVE | CVE-2022-41853 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-06 18:17:00 UTC |
| Updated | 2023-02-03 23:43:00 UTC |
| Description | Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Application | Hsqldb | Hypersql Database | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Chapter 9. SQL-Invoked Routines | MISC | hsqldb.org | |
| [SECURITY] [DLA 3234-1] hsqldb security update | MLIST | lists.debian.org | |
| Debian -- Security Information -- DSA-5313-1 hsqldb | DEBIAN | www.debian.org | |
| 50212 - oss-fuzz - OSS-Fuzz: Fuzzing the planet - Monorail | MISC | bugs.chromium.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160259 Oracle Enterprise Linux Security Update for hsqldb (ELSA-2022-8560)
- 160456 Oracle Enterprise Linux Security Update for hsqldb (ELSA-2023-12103)
- 181313 Debian Security Update for hsqldb (DLA 3234-1)
- 181466 Debian Security Update for hsqldb (DSA 5313-1)
- 184563 Debian Security Update for hsqldb (CVE-2022-41853)
- 240937 Red Hat Update for hsqldb (RHSA-2022:8560)
- 241301 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 on RHEL 7 (RHSA-2023:1512)
- 241302 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 on RHEL 8 (RHSA-2023:1513)
- 241303 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 on RHEL 9 (RHSA-2023:1514)
- 257204 CentOS Security Update for hsqldb (CESA-2022:8560)
- 354645 Amazon Linux Security Advisory for hsqldb : ALAS2-2023-1914
- 354681 Amazon Linux Security Advisory for hsqldb : ALAS-2023-1666
- 377795 Alibaba Cloud Linux Security Update for hsqldb (ALINUX2-SA-2022:0054)
- 673110 EulerOS Security Update for hsqldb (EulerOS-SA-2023-2147)
- 752758 SUSE Enterprise Linux Security Update for hsqldb (SUSE-SU-2022:3864-1)