Risk | High |
Patch available | YES |
Number of vulnerabilities | 20 |
CVE-ID | CVE-2021-23999 CVE-2021-29980 CVE-2021-29976 CVE-2021-29469 CVE-2021-29478 CVE-2021-29477 CVE-2021-29986 CVE-2021-29989 CVE-2021-29951 CVE-2021-29988 CVE-2021-23998 CVE-2021-23994 CVE-2021-23995 CVE-2021-29946 CVE-2021-24002 CVE-2021-29984 CVE-2021-29970 CVE-2021-29985 CVE-2021-29964 CVE-2021-29967 |
CWE-ID | CWE-277 CWE-119 CWE-400 CWE-190 CWE-264 CWE-125 CWE-787 CWE-416 CWE-20 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #18 is available. |
Vulnerable software Subscribe |
IBM Cloud Application Performance Management (APM) Server applications / Other server solutions |
Vendor | IBM Corporation |
Security Bulletin
This security bulletin contains information about 20 vulnerabilities.
EUVDB-ID: #VU52338
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-23999
CWE-ID:
Exploit availability:
Descriptionthe vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to the way Firefox handles Blob URLs. If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU55683
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-29980
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in a canvas object. A remote attacker can trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU54679
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-29976
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU56912
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2021-29469
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources, when a client is in monitoring mode. A remote attacker can trigger resource exhaustion and perform a regular expression denial of service (ReDoS) attack.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU52829
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-29478
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in COPY command for large intsets. A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system for Redis starting with 6.2. Vulnerability exploitation in older versions results in a corrupted RDB or DUMP payload.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU52828
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-29477
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in STRALGO LCS command. A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU55678
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-29986
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a race condition in getaddrinfo
when resolving DNS names. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note, the vulnerability affects Linux systems only.
Install update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU55685
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-29989
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU52852
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2021-29951
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to the way Mozilla Maintenance Service is installed in the Windows operating system. After installation the Mozilla Maintenance Service is granted SERVICE_START access to BUILTIN|Users
which, in a domain network, grants normal remote users access to start or stop the service. A local domain user can spam the "Stop" command and prevent the browser update service from operating.
The vulnerability affects only Firefox ESR installed on operating system Windows 10 build 1709 and older.
Install update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU55680
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-29988
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary condition when treating inline list-item element as a block element. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger an out-of-bounds read error and execute arbitrary code on the system.
Install update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU52337
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-23998
CWE-ID:
Exploit availability:
Descriptionthe vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to the way HTTP pages inherit a secure lock icon, when navigating from an HTTP page. A remote attacker can create a specially crafted webpage that through a series of complicated navigation will force the browser to display a secure lock icon on an unencrypted HTTP page.
Install update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU52333
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-23994
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input within the WebGL framebuffer. A remote attacker can create a specially crafted web page, trick the victim into opening it using the affected software, trigger out-of-bounds write and execute arbitrary code on the target system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU52334
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-23995
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input, when Responsive Design Mode is enabled. A remote attacker can create a specially crafted web page, trick the victim into opening it using the affected software, trigger a use-after-fee error and execute arbitrary code on the target system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU52346
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2021-29946
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input. Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc header.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU52341
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2021-24002
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input when processing newline characters in an FTP URL (such as %0A and %0D). A remote attacker can trick the victim to click on a specially crafted URL and execute arbitrary FTP commands on a remote server, given that victim has access to the FTP server.
Install update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU55682
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-29984
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when performing JIT optimization. A remote attacker can trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU54678
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-29970
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in accessibility features when processing HTML content. A remote attacker can track the victim to open a specially crafted web page, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU55684
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-29985
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a use-after-free error in media channels within the MediaCacheStream::NotifyDataReceived method. A remote attacker can trick the victim to open a specially crafted web page, trigger a use-after-free error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU53706
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2021-29964
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a local application to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition. A locally-installed hostile program could send WM_COPYDATA
messages that Firefox would processing incorrectly and will result in out-of-bounds read.
Note, the vulnerability affects Windows installations only.
Install update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU53707
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-29967
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can create a specially crafted webpage, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Application Performance Management (APM): 8.1.4
Fixed software versionsCPE2.3 External links
http://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-78-14-0-esr-cve-2021-29967-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if14/
http://www.ibm.com/support/pages/node/6493377
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?