CVE-2022-32287

HIGH

Apache UIMA < 3.3.0 - Path Traversal via ZIP Entry in PEAR File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-32287. PoCs published by shoucheng3.

AI-analyzed exploit summary The repository appears to be a fork or snapshot of the Apache UIMA project with no explicit exploit code or technical analysis related to CVE-2022-32287. It contains standard project files (e.g., CI workflows, issue templates) but lacks any PoC, scanner, or writeup specific to the vulnerability.

Description

A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. This issue affects Apache UIMA Apache UIMA version 3.3.0 and prior versions. Note that PEAR files should never be installed into an UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the same privileges as the host Java Virtual Machine.

Exploits (1)

nomisec STUB
by shoucheng3 · poc
https://github.com/shoucheng3/apache__uima-uimaj_CVE-2022-32287_3-3-0

The repository appears to be a fork or snapshot of the Apache UIMA project with no explicit exploit code or technical analysis related to CVE-2022-32287. It contains standard project files (e.g., CI workflows, issue templates) but lacks any PoC, scanner, or writeup specific to the vulnerability.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Apache UIMA Java SDK
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/11/03/4

Scores

CVSS v3 7.5
EPSS 0.0077
EPSS Percentile 74.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
apache/uimaj < 3.3.0
org.apache.uima/uimaj-core 0 - 3.3.1Maven
Published Nov 03, 2022
Tracked Since Feb 18, 2026