« Volver al listado

CVE-2022-39198

Estado: ModificadaCrítica (9.8)—

A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior versions; Apache Dubbo 3.1.x version 3.1.0 and prior versions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-39198",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-39198",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-13T14:48:24.261938Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache Dubbo",
          "versions": [
            {
              "status": "affected",
              "version": "Apache Dubbo 2.7.x",
              "versionType": "custom",
              "lessThanOrEqual": "2.7.17"
            },
            {
              "status": "affected",
              "version": "Apache Dubbo 3.0.x",
              "versionType": "custom",
              "lessThanOrEqual": "3.0.11"
            },
            {
              "status": "affected",
              "version": "Apache Dubbo 3.1.x",
              "versionType": "custom",
              "lessThanOrEqual": "3.1.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-10-18T19:15:10.213",
  "references": [
    {
      "url": "https://lists.apache.org/thread/8d3zqrkoy4jh8dy37j4rd7g9jodzlvkk",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread/8d3zqrkoy4jh8dy37j4rd7g9jodzlvkk",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@apache.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior versions; Apache Dubbo 3.1.x version 3.1.0 and prior versions."
    },
    {
      "lang": "es",
      "value": "Se presenta una vulnerabilidad de deserialización en Dubbo Hessian-Lite 3.2.12 y sus versiones anteriores, que podría conllevar a una ejecución de código malicioso. Este problema afecta a Apache Dubbo versión 2.7.x versión 2.7.17 y versiones anteriores; Apache Dubbo versión 3.0.x versión 3.0.11 y versiones anteriores; Apache Dubbo versión 3.1.x versión 3.1.0 y versiones anteriores"
    }
  ],
  "lastModified": "2026-06-17T04:57:53.880",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F736F4F-0B7F-418B-BC7F-CA7AB6B71069",
              "versionEndIncluding": "2.7.17",
              "versionStartIncluding": "2.7.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F17AA9B1-7F6C-446F-932B-22C2CD00800B",
              "versionEndIncluding": "3.0.11",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:dubbo:3.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CAB4AF18-AF88-4910-B694-9C7F3562C35C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}