Security restrictions bypass in Azure SDK for Java - CVE-2020-16971

 

Security restrictions bypass in Azure SDK for Java - CVE-2020-16971

Published: December 8, 2020


Vulnerability identifier: #VU48887
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16971
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and remote code execution.


Affected software

Azure SDK for Java
Operations Analytics - Log Analysis
IBM Qradar SIEM
Juniper Secure Analytics (JSA)

How to mitigate CVE-2020-16971

Install updates from vendor's website.

Operations Analytics - Log Analysis - update to 1.3.8 Fix Pack 3
Juniper Secure Analytics (JSA) - update to 7.5.0 UP14 IF01

External References

Related Security Bulletins