CVE-2022-42889None

CVE-2022-42889 Impact of Apache Text Commons Vulnerability CVE-2022-42889

Published
November 9, 2022
Last Modified
November 9, 2022

🔗 CVE IDs covered (1)

📋 Description

Palo Alto Networks has evaluated the Apache Commons Text library vulnerability CVE-2022-42889, known as Text4Shell, for all products and services. The Palo Alto Networks Product Security Assurance team has confirmed that all products and services are not impacted by this vulnerability.

🎯 Affected products26

  • PAN-OS
  • Cortex XDR Agent
  • GlobalProtect App
  • Cortex XSOAR
  • WildFire Appliance (WF-500)
  • Expanse
  • Okyo Garde
  • Palo Alto Networks App for Splunk
  • Prisma Cloud Compute
  • Expedition Migration Tool
  • IoT Security
  • User-ID Agent
  • Exact Data Matching CLI
  • Bridgecrew
  • Cortex Xpanse
  • Enterprise Data Loss Prevention
  • Prisma SD-WAN (CloudGenix)
  • Prisma SD-WAN ION
  • SaaS Security
  • Cortex Data Lake
  • AutoFocus
  • WildFire Cloud
  • Prisma Cloud
  • Cloud NGFW
  • Prisma Access
  • Cortex XDR

✅ Remediation

No software updates are required at this time. Workarounds and mitigations: Customers with a Threat Prevention subscription can block known attacks for CVE-2022-42889 by enabling Threat ID 93157 (Applications and Threats content update 8632). This mitigation reduces the risk of exploitation from known exploits.

🔗 References (1)