RULE(RULE ID:337607)

Rule General Information
Release Date: 2023-08-08
Rule Name: Apache Commons Jxpath Command Execution Vulnerability (CVE-2022-41852)
Severity:
CVE ID:
Rule Protection Details
Description: Those using JXPath to interpret untrusted XPath expressions may be vulnerable to a remote code execution attack. All JXPathContext class functions processing a XPath string are vulnerable except compile() and compilePath() function. The XPath expression can be used by an attacker to load any Java class from the classpath resulting in code execution.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://bugs.chromium.org/p/oss-fuzz/issues/detail
https://cxsecurity.com/cveshow/CVE-2022-41852/
Solutions
Refer to the announcement or patch by the vendor: https://bugs.chromium.org/p/oss-fuzz/issues/detail