Apr 13 2023

T22-2023 BIOVIA Pipeline Pilot: Scope of Vulnerability CVE-2022-42915

BIOVIA Pipeline Pilot

Technical Note T22-2023

April 2023

BIOVIA Pipeline Pilot: Scope of Vulnerability CVE-2022-42915

Program

BIOVIA Pipeline Pilot

Operating System

All supported operating systems

Background

As part of Pipeline Pilot, we bundle DataDirect Drivers to allow ODBC connectivity.

The DataDirect supplier has informed us of a vulnerability (CVE-2022-42915) in some ODBC drivers which are currently shipped with curl version 7.84. This vulnerability affects the following drivers shipped with Pipeline Pilot

·         Oracle 8.0 ODBC

·         SQLServer 8.0 ODBC

·         DB2 8.0 ODBC

 

but only when:

a)    Pipeline Pilot connects to a database server over an HTTP proxy AND

b)    the URL for the transfer uses one of these specific communication schemes, where a double-free is possible during cleanup: dict, gopher, gophers, ldap, ldaps, rtmp, rtmps, or telnet.

Solution

We believe it is unlikely that any Pipeline Pilot installation is affected by this vulnerability, and we are only providing this information in a spirit of full transparency.

BIOVIA Pipeline Pilot does not require or expect an HTTP proxy to connect to databases using DataDirect Drivers, and indeed it cannot be set up via Pipeline Pilot configuration.

Pipeline Pilot ODBC components do not make use of the affected schemes. You will only be affected by this issue if you have made your own custom configuration changes to use an HTTP proxy and have engineered components to make use of one of the affected schemes.

In the unlikely event that you believe that your installation of Pipeline Pilot is impacted, then the advice from DataDirect is to avoid using the HTTP proxy as a short-term workaround.

How to contact BIOVIA Support

If you have any questions, please contact BIOVIA Support.