Cleartext transmission of sensitive information in Apache MINA - CVE-2019-0231

 

Cleartext transmission of sensitive information in Apache MINA - CVE-2019-0231

Published: March 19, 2020


Vulnerability identifier: #VU26209
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0231
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to incorrect handling of close_notify SSL/TLS messages that results in software not closing the connection and retaining the socket opened, which allows a client to receive clear text messages afterward. A remote attacker can intercept traffic between client and server application and gain access to potentially sensitive information.


Affected software

Apache MINA
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Zimbra Collaboration
IBM Common Licensing
Oracle Access Manager
IBM Cognos Analytics

How to mitigate CVE-2019-0231

Install updates from vendor's website.

Apache MINA - addressed in versions 2.0.21, 2.1.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.7.0
Zimbra Collaboration - addressed in versions 8.8.15 Patch 32, 9.0.0 Patch 25
IBM Common Licensing - update to 9.0.0.2
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.3 IF1

External References

Related Security Bulletins