CVE-2022-35737 describes an array-bounds overflow vulnerability in SQLite versions 1.0.12 through 3.39.x before 3.39.2, which can occur when processing string arguments of billions of bytes via its C API. This flaw impacts various products, including NetApp, Splunk, and other SQLite implementations. With a CVSS score of 7.5 (HIGH), it presents a high availability impact without requiring user interaction or privileges, though it has a low attack complexity. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness despite its inactive status on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.12, < 3.39.2CPE matchmatch criteria | cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:* | ||
>= 8.2.0, < 8.2.12CPE matchmatch criteria | cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.6CPE matchmatch criteria | cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:* | ||
9.1.0CPE matchmatch criteria | cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MITRE: CVE-2022-35737 SQLite allows an array-bounds overflow
Jan 9, 2024August Third Party Package Updates in Splunk Universal Forwarder
Aug 30, 2023August 2023 Third Party Package Updates in Splunk Enterprise
Aug 30, 2023CVE-2022-35737
Aug 9, 2022`libsqlite3-sys` via C SQLite improperly validates array index
Aug 4, 2022sqlite: an array-bounds overflow if billions of bytes are used in a string argument to a C API
Jul 22, 2022