Code Injection in Apache Commons Configuration - CVE-2020-1953
Published: March 17, 2020
Vulnerability identifier: #VU26146
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1953
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure configuration of third-party library for parsing YAML files. A remote attacker with ability to pass YAML file to the application can inject and execute arbitrary code on the system.
Affected software
Apache Commons Configuration
Oracle Healthcare Foundation
Sterling Connect Direct File Agent
Jazz Reporting Service
AMQ Broker
Oracle Healthcare Foundation
Sterling Connect Direct File Agent
Jazz Reporting Service
AMQ Broker
How to mitigate CVE-2020-1953
Install updates from vendor's website.
Apache Commons Configuration - update to 2.7
Sterling Connect Direct File Agent - update to 1.4.0.2.8
Jazz Reporting Service - update to 7.0.2 iFix021
AMQ Broker - addressed in versions 7.4.4, 7.7
Sterling Connect Direct File Agent - update to 1.4.0.2.8
Jazz Reporting Service - update to 7.0.2 iFix021
AMQ Broker - addressed in versions 7.4.4, 7.7
External References
Related Security Bulletins
- Code injection when parsing YAML files in Apache Commons Configuration
- Multiple vulnerabilities in Oracle Healthcare Foundation
- Code Injection in IBM Sterling Connect:Direct File Agent
- Multiple vulnerabilities in IBM Jazz Reporting Service
- Multiple vulnerabilities in AMQ Broker 7
- Multiple vulnerabilities in AMQ Broker 7.4