Reliance on Reverse DNS Resolution for a Security-Critical Action in Apache Camel - CVE-2020-11971
Published: May 17, 2020
Vulnerability identifier: #VU27956
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11971
CWE-ID: CWE-350
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to Apache Camel JMX is vulnerable to DNS rebinding attack. A remote attacker can send specially crafted data to the application and perform spoofing attack.
Affected software
Apache Camel
Jazz for Service Management
IBM Tivoli Monitoring
IBM Tivoli Netcool Impact
Oracle Communications Diameter Intelligence Hub
SecureTransport
IBM Qradar SIEM
UrbanCode Build
Jazz for Service Management
IBM Tivoli Monitoring
IBM Tivoli Netcool Impact
Oracle Communications Diameter Intelligence Hub
SecureTransport
IBM Qradar SIEM
UrbanCode Build
How to mitigate CVE-2020-11971
Install updates from vendor's website.
Apache Camel - addressed in versions 2.25.1, 3.2.0
Jazz for Service Management - update to 1.1.3.25
SecureTransport - update to 5.5-20230629
IBM Tivoli Monitoring - update to 6.3.0.7 Service pack 13
IBM Tivoli Netcool Impact - update to 7.1.0.27
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
UrbanCode Build - update to 6.1.7.10
Jazz for Service Management - update to 1.1.3.25
SecureTransport - update to 5.5-20230629
IBM Tivoli Monitoring - update to 6.3.0.7 Service pack 13
IBM Tivoli Netcool Impact - update to 7.1.0.27
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
UrbanCode Build - update to 6.1.7.10
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Camel
- Multiple vulnerabilities in Oracle Communications Diameter Intelligence Hub
- Spoofing attack in IBM Tivoli Netcool Impact
- Spoofing attack in in IBM Tivoli Monitoring Data Provider
- IBM QRadar SIEM update for third-party components
- Multiple vulnerabilities in Axway SecureTransport
- Multiple vulnerabilities in IBM UrbanCode Build
- Multiple vulnerabilities in IBM Jazz for Service Management