9.8
CVSSv3

CVE-2022-42920

Published: 07/11/2022 Updated: 17/01/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache commons bcel

fedoraproject fedora 35

fedoraproject fedora 36

fedoraproject fedora 37

Vendor Advisories

Synopsis Important: rh-maven36-bcel security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rh-maven36-bcel is now available for Red Hat Software CollectionsRed Hat Product Security has rated this u ...
Synopsis Important: bcel security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for bcel is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a securi ...
Synopsis Important: bcel security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for bcel is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a securi ...
Synopsis Critical: Red Hat Fuse 712 release and security update Type/Severity Security Advisory: Critical Topic A minor version update (from 711 to 712) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security has rated this update as h ...
Synopsis Important: Red Hat Process Automation Manager 7134 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which ...
Synopsis Important: Migration Toolkit for Runtimes security update Type/Severity Security Advisory: Important Topic An update is now available for Migration Toolkit for Runtimes (v101)Red Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Scoring System (CVSS) base score, whichgives a ...
Synopsis Important: Migration Toolkit for Applications security and bug fix update Type/Severity Security Advisory: Important Topic Migration Toolkit for Applications 601 releaseRed Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Scoring System (CVSS) base score, whichgives a detail ...
Synopsis Important: Migration Toolkit for Runtimes security update Type/Severity Security Advisory: Important Topic An update is now available for Migration Toolkit for Runtimes (v101)Red Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Scoring System (CVSS) base score, whichgives a ...
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resu ...
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resu ...
DescriptionThe MITRE CVE dictionary describes this issue as: Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode This could be abused in applications that pass attacker-controllable data ...
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resu ...

Github Repositories

Modern Java/JVM Build Practices

Modern Java/JVM Build Practices Modern Java/JVM Build Practices is an article-as-repo on building modern Java/JVM projects using Gradle and Maven, and a starter project for Java The focus is best build practices and project hygiene This document is agnostic between Gradle and Maven: discussion in each section covers both tools (alphabetical order, Gradle before Maven) S