CVE-2022-42920
Commons BCEL Bytecode Injection: stopped at runtime
Waratek RASP already blocks this exploit at runtime, inside the JVM - with no application change, no vendor patch, and no downtime.
Published November 7, 2022 · Updated March 4, 2026
The vulnerability
Remote code execution via attacker-controlled Java bytecode generation
Several Commons BCEL APIs that are meant to only tweak specific, narrow class characteristics have an out-of-bounds write defect that lets them be abused to produce arbitrary Java bytecode instead. An application that passes attacker-controllable data into these APIs gives the attacker far more control over the generated class than intended, letting a crafted class be loaded and executed for remote code execution.
Running an affected version? We can help.
Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.
How Waratek RASP stops it
Blocked at runtime by Waratek RASP
Waratek RASP ships a patch rule that blocks exploitation at the exact point the dangerous operation is attempted, inside the JVM.
Runtime, not perimeter
Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.
No code changes
Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.
Zero false positives
Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.
| Mod | Rules | Enable |
|---|---|---|
| Commons BCEL Bytecode Injection protectionCVE-2022-42920 · Out-of-bounds write (unsafe bytecode generation) | 1 | |
| SQL Injection protectionQuery manipulation | 4 | |
| Path Traversal protectionUnsafe file access | 3 |
Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.
Common questions
Commons BCEL Bytecode Injection FAQ
Is Commons BCEL Bytecode Injection (CVE-2022-42920) exploitable?
CVE-2022-42920 carries a CVSS 9.8/10 (CRITICAL) rating and affects Apache Commons BCEL before 6.6.0. Several Commons BCEL APIs that are meant to only tweak specific, narrow class characteristics have an out-of-bounds write defect that lets them be abused to produce arbitrary Java bytecode instead. An application that passes attacker-controllable data into these APIs gives the attacker far more control over the generated class than intended, letting a crafted class be loaded and executed for remote code execution.
How does Waratek mitigate Commons BCEL Bytecode Injection (CVE-2022-42920)?
Waratek RASP blocks exploitation of Commons BCEL Bytecode Injection (CVE-2022-42920) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.
Protect your apps in production
Get protected against Commons BCEL Bytecode Injection - without code changes or redeploying
Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2022-42920 and attacks like it, and get you covered in production.