Impact
CVE-2022-46337 affects Apache Derby's LDAP authenticator in multiple Derby 10.x release lines [S1][S2][S3]. Public advisory sources describe LDAP injection risk when Derby is configured to authenticate users against an external LDAP directory [S1][S2][S4].
The advisory is rated critical by upstream vulnerability databases because an exposed vulnerable Derby deployment with LDAP authentication can let unauthenticated input alter the directory query used for authentication [S1][S3]. Runtime impact still depends on whether the affected Derby version is actually deployed, LDAP authentication is enabled, SQL authorization is enforced, and the database service is reachable by untrusted users [S1][S4].
Root Cause
Affected Derby releases did not safely handle user-controlled authentication values before using them in LDAP lookup filters [S1][S2][S4]. Apache tracks the fix under DERBY-7147 and lists fixed Derby releases for the maintained 10.14, 10.15, 10.16, and 10.17 lines [S4].
Affected Versions
Advisory sources list affected Maven package org.apache.derby:derby ranges across Derby 10.x [S1][S2]:
- 10.1.1.0 through 10.1.3.1.
- 10.2.1.6 through 10.2.2.0.
- 10.3.1.4 through 10.3.3.0.
- 10.4.1.3 through 10.4.2.0.
- 10.5.1.1 through 10.5.3.0.
- 10.6.1.0 through 10.6.2.1.
- 10.7.1.1.
- 10.8.1.2 through 10.8.3.0.
- 10.9.1.0.
- 10.10.1.1 through 10.10.2.0.
- 10.11.1.1, 10.12.1.1, and 10.13.1.1.
- 10.14.2.0, fixed in 10.14.2.1.
- 10.15.1.3 through 10.15.2.0, fixed in 10.15.2.1.
- 10.16.1.1, fixed in 10.16.1.2.
Apache and GitHub recommend Derby 10.17.1.0 for current Java runtimes, with documented backported fixed releases for older supported Java baselines [S1][S4].
How FixVibe covers it
FixVibe's GitHub repo scans flag Maven and Gradle projects that resolve org.apache.derby:derby versions in the affected ranges, showing the file, version or constraint and the fixed release. Upgrade first wherever Derby runs with LDAP authentication enabled.
Fixes and Mitigations
Upgrade Apache Derby to 10.17.1.0 where possible, or to a documented fixed backport such as 10.14.2.1, 10.15.2.1, or 10.16.1.2 when that release family is intentionally maintained [S1][S4]. Update Maven or Gradle dependency sources, dependency-management or platform metadata, application-server bundled libraries, container images, package caches, and every deployed artifact that can load Derby.
After upgrading, verify the active Maven or Gradle dependency graph resolves the fixed Derby version and rebuild each JAR, WAR, worker, test database, embedded database bundle, application-server image, or container image that can include Derby. If Derby LDAP authentication is used, confirm the patched runtime is serving the environment, keep SQL GRANT/REVOKE authorization enabled, restrict Derby Network Server exposure, and review authentication/database-creation logs according to your incident-response policy [S1][S4].
