Skip to Main Content

SQL Developer

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Mitigating Apache Commons Text Exploit - CVE-2022-42889

user-j3gb9Apr 24 2023 — edited Apr 24 2023

Hi

I am trying to mitigate the exploit found in CVE-2022-42889 - CVE.report

Apache commons text versions 1.5 to 1.9 is vulnerable and found in SQL developer 22.2

According to this twitter post you can mitigate it by removing the graph feature:

Shortened Twitter link: https://twtr.in/3PkW

I have tried this by deleting the following folder:

\sqldeveloper\sqldeveloper\extensions\oracle.sqldeveloper.pgql

But when I open SQL developer application I can still enable or disable the property graph feature:

I am not a user of SQL developer so might be missing something here. Can anyone give some advice on removing or disabling the Graph Feature through registry or file system?

Comments
Post Details
Added on Apr 24 2023
4 comments
1,023 views