Insecure Temporary File in JUnit - CVE-2020-15250

 

Insecure Temporary File in JUnit - CVE-2020-15250

Published: October 12, 2020 / Updated: January 7, 2021


Vulnerability identifier: #VU49330
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15250
CWE-ID: CWE-377
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to the application is using the test rule TemporaryFolder that stores sensitive information in temporary files in the system temporary directory, accessible by other system users. A local user can read temporary files and obtain sensitive information, related to the application.


Affected software

JUnit
API Manager
Oracle Banking Liquidity Management
API Gateway
Oracle WebLogic Server
TensorFlow
Netcool/OMNIbus
IBM Cloud Pak for Business Automation
IBM Cloud Pak for Security
IBM Cloud Transformation Advisor
IBM Sterling B2B Integrator
Tivoli Composite Application Manager for Transactions
IBM Disconnected Log Collector
JD Edwards EnterpriseOne Tools
Oracle Communications Cloud Native Core Policy
Apache Pulsar
Voice Gateway
junit (Alpine package)
junit4-doc (Ubuntu package)
junit4 (Ubuntu package)
junit
junit-help
Knowledge Catalog Premium Cartridge
IBM Business Automation Manager Open Editions
Business Automation Insights
IBM Security Risk Manager
Cloudera Observability with IBM
Engineering Test Management
MongoDB Enterprise Advanced with IBM
IBM Security Guardium
Ubuntu
openEuler
watsonx.data

How to mitigate CVE-2020-15250

Install updates from vendor's website.

JUnit - update to 4.13.1
API Manager - update to August 2022
API Gateway - update to August 2022
TensorFlow - addressed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2
IBM Disconnected Log Collector - update to 1.8.7
Apache Pulsar - update to 2.8.0
Knowledge Catalog Premium Cartridge - update to 5.2
Netcool/OMNIbus - update to 8.1.0.37
IBM Business Automation Manager Open Editions - update to 9.2.1
JD Edwards EnterpriseOne Tools - update to 9.2.7.3
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF005, 24.0.1-IF004, 25.0.0
Business Automation Insights - update to 24.0.1.0.4
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
IBM Security Risk Manager - update to 1.8.0.0
IBM Cloud Pak for Security - update to 1.11.2.0
watsonx.data - update to 2.0.1
Cloudera Observability with IBM - update to 3.6.2
IBM Cloud Transformation Advisor - update to 3.6.2
junit4-doc (Ubuntu package) - addressed in versions 4.12-4ubuntu1.1, 4.12-8ubuntu0.20.04.1, 4.12-8ubuntu0.20.10.1, 4.12-8~18.04.1
junit4 (Ubuntu package) - addressed in versions 4.12-4ubuntu1.1, 4.12-8ubuntu0.20.04.1, 4.12-8ubuntu0.20.10.1, 4.12-8~18.04.1
junit - update to 4.12-13
junit-help - update to 4.12-13
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.6, 6.1.1.1, 6.1.2.0
Engineering Test Management - addressed in versions 7.0.1.0.22, 7.0.2.0.23
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
MongoDB Enterprise Advanced with IBM - update to 8.0.12

External References

Related Security Bulletins