Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-42920

33
FAUCET Score

CVE-2022-42920 is a critical out-of-bounds write vulnerability in Apache Commons BCEL, affecting versions of apache commons_bcel and fedoraproject fedora. This flaw allows attackers to manipulate specific APIs to generate arbitrary bytecode, potentially granting them significant control over applications that process attacker-controlled data. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion, indicating awareness and potential interest among researchers.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.6.0CPE matchmatch criteria
cpe:2.3:a:apache:commons_bcel:*:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
37CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.84%
Probability of exploitation in next 30 days
EPSS Percentile
85.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0284 is in the 76th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (23)

mavenpatch availablevia ghsa
Product: org.apache.bcel:bcelFixed in: 6.6.0
redhatpatch availablevia redhat_api
Product: Migration Toolkit for Runtimes 1 on RHEL 8Fixed in: mtr/mtr-operator-bundle:1.0-30
View patch
redhatpatch availablevia redhat_api
Product: Migration Toolkit for Runtimes 1 on RHEL 8Fixed in: mtr/mtr-rhel8-operator:1.0-10
View patch
redhatpatch availablevia redhat_api
Product: Migration Toolkit for Runtimes 1 on RHEL 8Fixed in: mtr/mtr-web-container-rhel8:1.0-15
View patch
redhatpatch availablevia redhat_api
Product: Migration Toolkit for Runtimes 1 on RHEL 8Fixed in: mtr/mtr-web-executor-container-rhel8:1.0-14
View patch
redhatpatch availablevia redhat_api
Product: Migration Toolkit for Runtimes 1 on RHEL 8Fixed in: org.jboss.windup-windup-parent
View patch
redhatpatch availablevia redhat_api
Product: MTA-6.0-RHEL-8Fixed in: mta/mta-ui-rhel8:6.0.1-10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 2.7.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: bcel-0:5.2-19.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: bcel-0:6.4.1-9.el9_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: bcel-0:6.4.1-9.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.12Fixed in: apache-bcel
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-maven36-bcel-0:6.3.1-2.3.el7
View patch
redhatpatch availablevia redhat_api
Product: RHPAM 7.13.4 asyncFixed in: apache-bcel
View patch
redhatno patchvia redhat_api
Product: Migration Toolkit for Applications 6Fixed in: org.jboss.windup-windup-cli-parent
redhatno patchvia redhat_api
Product: Migration Toolkit for RuntimesFixed in: org.jboss.windup.plugin-windup-maven-plugin
redhatno patchvia redhat_api
Product: Migration Toolkit for RuntimesFixed in: org.jboss.windup.plugin-windup-maven-plugin-parent
redhatno patchvia redhat_api
Product: Migration Toolkit for RuntimesFixed in: org.jboss.windup.rules-windup-rulesets
redhatno patchvia redhat_api
Product: Migration Toolkit for RuntimesFixed in: org.jboss.windup.rules-windup-rulesets-parent
redhatno patchvia redhat_api
Product: Migration Toolkit for RuntimesFixed in: org.jboss.windup.web-windup-web-parent
redhatno patchvia redhat_api
Product: Migration Toolkit for RuntimesFixed in: org.jboss.windup-windup-cli-parent
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: bcel
redhatno patchvia redhat_api
Product: Red Hat Single Sign-On 7Fixed in: apache-bcel

Vendor Advisories (2)

mavenGHSA-97xg-phpr-rg8qcritical

Apache Commons BCEL vulnerable to out-of-bounds write

Nov 7, 2022
redhatCVE-2022-42920Important

Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing

Nov 4, 2022

References

lists.apache.org / thread/lfxk7q8qmnh5bt9jm6nmjlv5hsxjhrz4
Mailing ListVendor Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/LX3HEB4TV2BVCGDTK5BCLSYOZNQTOBN4
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QAMRHAKGIKZNHRBB4VLYTOIOIMMXCUCD
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QMVX6COVXZVS5GPWDODIRW6Z2GE7RPAQ
security.gentoo.org / glsa/202401-25
openwall.com / lists/oss-security/2022/11/07/2
Mailing ListThird Party Advisory