Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-42920

Опубликовано: 07 нояб. 2022
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:commons_bcel:*:*:*:*:*:*:*:*
Версия до 6.6.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.03792
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

CVSS3: 8.1
redhat
больше 2 лет назад

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

CVSS3: 9.8
debian
больше 2 лет назад

Apache Commons BCEL has a number of APIs that would normally only allo ...

suse-cvrf
больше 2 лет назад

Security update for bcel

suse-cvrf
больше 2 лет назад

Security update for bcel

EPSS

Процентиль: 88%
0.03792
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787