Vulnerability record · CVE-2022-32287 · published 3 November 2022
CVE-2022-32287: Apache uimaj path traversal vulnerability
Apache · Uimaj
A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. This issue affects Apache UIMA Apache UIMA version 3.3.0 and prior versions. Note that PEAR files should never be installed into an UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the same privileges as the host Java Virtual Machine.
Description
A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. This issue affects Apache UIMA Apache UIMA version 3.3.0 and prior versions. Note that PEAR files should never be installed into an UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the same privileges as the host Java Virtual Machine.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2022/11/03/4 | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/57vk0d79j94d0lk0vol8xn935yv1shdd | Mailing ListVendor Advisory |
| http://www.openwall.com/lists/oss-security/2022/11/03/4 | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/57vk0d79j94d0lk0vol8xn935yv1shdd | Mailing ListVendor Advisory |
Track CVE-2022-32287 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-32287), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.