Vulnerability Name:

CVE-2022-1586 (CCN-226863)

Assigned:2022-03-23
Published:2022-03-23
Updated:2023-03-16
Summary:An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.
CVSS v3 Severity:9.1 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
7.9 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): High
7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
7.5 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-125
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2022-1586

Source: CCN
Type: Red Hat Bugzilla - Bug 2077976
(CVE-2022-1586) - CVE-2022-1586 pcre2: Out-of-bounds read in compile_xclass_matchingpath in pcre2_jit_compile.c

Source: secalert@redhat.com
Type: Broken Link, Issue Tracking, Patch
secalert@redhat.com

Source: XF
Type: UNKNOWN
pcre2-cve20221586-code-exec(226863)

Source: CCN
Type: PCRE2 GIT Repository
pcre2

Source: secalert@redhat.com
Type: Broken Link
secalert@redhat.com

Source: secalert@redhat.com
Type: Patch, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: IBM Security Bulletin 6616631 (MQ Operator)
BM MQ Operator and Queue manager container images are vulnerable to multiple vulnerabilities from openssl, pcre2 and Golang Go

Source: CCN
Type: IBM Security Bulletin 6831591 (Robotic Process Automation)
Multiple Security Vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak

Source: CCN
Type: IBM Security Bulletin 6837579 (App Connect Enterprise Certified Container)
IBM App Connect Enterprise Certified Container operands may be vulnerable to arbitrary code execution due to CVE-2022-1586

Source: CCN
Type: IBM Security Bulletin 6843869 (Watson Speech Services Cartridge for Cloud Pak for Data)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data is vulnerable to arbitrary code execution in PCRE2 (CVE-2022-1586)

Source: CCN
Type: IBM Security Bulletin 6848225 (Netcool Operations Insight)
Netcool Operations Insight v1.6.7 contains fixes for multiple security vulnerabilities.

Source: CCN
Type: IBM Security Bulletin 6952553 (Aspera Orchestrator)
IBM Aspera Orchestrator affected by vulnerability (CVE-2022-1586)

Source: CCN
Type: IBM Security Bulletin 6958506 (Security QRadar SIEM)
IBM QRadar SIEM Application Framework Base Image is vulnerable to using components with Known Vulnerabilities

Source: CCN
Type: IBM Security Bulletin 7001867 (Cloud Pak for Security)
IBM Cloud Pak for Security includes components with multiple known vulnerabilities

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:9:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:9::appstream:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:9:*:*:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:9::baseos:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/a:redhat:enterprise_linux:8::crb:*:*:*:*:*
  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:8::baseos:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:pcre:pcre2:10.39:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:robotic_process_automation:21.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:robotic_process_automation:21.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:app_connect_enterprise_certified_container:4.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:app_connect_enterprise_certified_container:4.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:robotic_process_automation:21.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:robotic_process_automation:21.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.10.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:app_connect_enterprise_certified_container:5.0:*:*:*:lts:*:*:*
  • OR cpe:/a:ibm:app_connect_enterprise_certified_container:5.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.4:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7640
    P
    libpcre1-32bit-8.45-150000.20.13.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7641
    P
    libpcre2-16-0-10.39-150400.4.6.1 on GA media (Moderate)
    2023-06-12
    oval:com.redhat.rhsa:def:20225809
    P
    RHSA-2022:5809: pcre2 security update (Moderate)
    2022-08-03
    oval:org.opensuse.security:def:94046
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:574
    P
    Security update for pcre (Important)
    2022-07-12
    oval:org.opensuse.security:def:93315
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:94467
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:93627
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:93154
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:43643
    P
    Security update for pcre (Important)
    2022-07-12
    oval:org.opensuse.security:def:118758
    P
    Security update for pcre (Important)
    2022-07-12
    oval:org.opensuse.security:def:94047
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:93472
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:42315
    P
    Security update for pcre (Important)
    2022-07-12
    oval:org.opensuse.security:def:119253
    P
    Security update for pcre (Important)
    2022-07-12
    oval:org.opensuse.security:def:94468
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:93832
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:93155
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:119629
    P
    Security update for pcre (Important)
    2022-07-12
    oval:org.opensuse.security:def:3630
    P
    Security update for pcre2 (Important)
    2022-07-12
    oval:org.opensuse.security:def:94258
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:93473
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:95260
    P
    Security update for pcre2 (Important)
    2022-07-12
    oval:org.opensuse.security:def:93833
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:573
    P
    Security update for pcre2 (Important)
    2022-07-12
    oval:org.opensuse.security:def:93314
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:3631
    P
    Security update for pcre (Important)
    2022-07-12
    oval:org.opensuse.security:def:118948
    P
    Security update for pcre (Important)
    2022-07-12
    oval:org.opensuse.security:def:94259
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:93626
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:42410
    P
    Security update for pcre (Important)
    2022-07-12
    oval:org.opensuse.security:def:119444
    P
    Security update for pcre (Important)
    2022-07-12
    oval:org.opensuse.security:def:95261
    P
    Security update for pcre (Important)
    2022-07-12
    oval:org.opensuse.security:def:4298
    P
    Security update for pcre (Important)
    2022-07-08
    oval:org.opensuse.security:def:125752
    P
    Security update for pcre (Important)
    2022-07-08
    oval:org.opensuse.security:def:6093
    P
    Security update for pcre (Important)
    2022-07-08
    oval:org.opensuse.security:def:127313
    P
    Security update for pcre (Important)
    2022-07-08
    oval:org.opensuse.security:def:6342
    P
    Security update for pcre (Important)
    2022-07-08
    oval:org.opensuse.security:def:125114
    P
    Security update for pcre (Important)
    2022-07-08
    oval:org.opensuse.security:def:5291
    P
    Security update for pcre (Important)
    2022-07-08
    oval:org.opensuse.security:def:126916
    P
    Security update for pcre (Important)
    2022-07-08
    oval:com.redhat.rhsa:def:20225251
    P
    RHSA-2022:5251: pcre2 security update (Moderate)
    2022-07-01
    oval:org.opensuse.security:def:934
    P
    Security update for pcre (Important) (in QA)
    2022-06-23
    oval:org.opensuse.security:def:42295
    P
    Security update for pcre2 (Important)
    2022-05-30
    oval:org.opensuse.security:def:119218
    P
    Security update for pcre2 (Important)
    2022-05-30
    oval:org.opensuse.security:def:905
    P
    Security update for pcre2 (Important)
    2022-05-30
    oval:org.opensuse.security:def:119593
    P
    Security update for pcre2 (Important)
    2022-05-30
    oval:org.opensuse.security:def:118912
    P
    Security update for pcre2 (Important)
    2022-05-30
    oval:org.opensuse.security:def:42394
    P
    Security update for pcre2 (Important)
    2022-05-30
    oval:org.opensuse.security:def:119408
    P
    Security update for pcre2 (Important)
    2022-05-30
    oval:org.opensuse.security:def:118722
    P
    Security update for pcre2 (Important)
    2022-05-30
    oval:org.opensuse.security:def:125720
    P
    Security update for pcre2 (Important)
    2022-05-25
    oval:org.opensuse.security:def:6054
    P
    Security update for pcre2 (Important)
    2022-05-25
    oval:org.opensuse.security:def:127282
    P
    Security update for pcre2 (Important)
    2022-05-25
    oval:org.opensuse.security:def:5260
    P
    Security update for pcre2 (Important)
    2022-05-25
    oval:org.opensuse.security:def:126885
    P
    Security update for pcre2 (Important)
    2022-05-25
    BACK
    pcre pcre2 10.39
    ibm robotic process automation 21.0.1
    ibm robotic process automation 21.0.2
    ibm app connect enterprise certified container 4.1
    ibm app connect enterprise certified container 4.2
    ibm robotic process automation 21.0.3
    ibm robotic process automation 21.0.4
    ibm cloud pak for security 1.10.0.0
    ibm app connect enterprise certified container 5.0
    ibm app connect enterprise certified container 5.1
    ibm qradar security information and event manager 7.4 -