Input validation error in Play Framework and Netty - CVE-2015-2156

 

Input validation error in Play Framework and Netty - CVE-2015-2156

Published: October 18, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38060
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-2156
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.


Affected software

Play Framework
Netty
IBM PureData System for Operational Analytics
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Spectrum Protect Plus
Operations Analytics - Log Analysis
StreamSets Data Collector
Fedora
watsonx.data
netty

How to mitigate CVE-2015-2156

Install update from vendor's website.

Operations Analytics - Log Analysis - update to 1.3.8.4
watsonx.data - update to 2.0.2
netty - addressed in versions 4.0.28-1.fc21, 4.0.28-1.fc22
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.8.0
StreamSets Data Collector - update to 7.0.0
IBM Spectrum Protect Plus - update to 10.1.6.4

External References

Related Security Bulletins