Resource exhaustion in Jetty - CVE-2021-28165
Published: April 1, 2021 / Updated: November 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing large TLS frames. A remote attacker can send specially crafted data to the server, trigger CPU high load and perform a denial of service (DoS) attack.
Affected software
IBM Business Automation Workflow
IBM Process Mining
Crowd Data Center
Jira Software Data Center
IBM Customer and Network Analytics for Communications Service Providers and Datasets
IBM Integration Bus
Netcool Operations Insight
Red Hat Integration Camel-K
IBM MaaS360 Mobile Enterprise Gateway
Datastax Enterprise with IBM
IBM Cloud Application Performance Management (APM)
IBM Spectrum Protect Storage Agent
Dell NetWorker Virtual Edition
Security Directory Integrator
Cloudera Observability with IBM
Rational Performance Tester
IBM Security Verify Directory
IBM Enterprise Records
Engineering Lifecycle Management - Jazz Foundation
IBM Security Directory Suite
Dell Security Management Server
Red Hat Developer Tools
IBM App Connect Enterprise
Oracle REST Data Services
Sterling Connect:Direct Browser User Interface
Rational Change
Oracle Unified Directory
AMQ Streams
Jenkins LTS
Jenkins
Oracle Communications Converged Application Server
AMQ Broker
Oracle Communications Cloud Native Core Policy
IBM Analytic Accelerator Framework for Communication Service Providers
Red Hat OpenShift Container Platform
Traffix SDC
Oracle Autovue for Agile Product Lifecycle Management
Crowd Server
IBM Qradar SIEM
Jira Software Server
IBM Cognos Command Center
Zimbra Collaboration
SUSE Linux Enterprise Module for Development Tools
openEuler
Fedora
Siebel CRM End User
runc (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
ignition (Red Hat package)
jenkins (Red Hat package)
openshift-ansible (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
jetty-start
jetty-unixsocket
jetty-server
jetty-jmx
jetty-cdi
jetty-proxy
jetty-http2-common
jetty-webapp
jetty-websocket-common
jetty-osgi-boot-warurl
jetty-jstl
jetty-util-ajax
jetty-http
jetty-websocket-server
jetty-jspc-maven-plugin
jetty-http2-hpack
jetty-annotations
jetty-jsp
jetty-alpn-client
jetty-client
jetty-http2-server
jetty-jaspi
jetty-quickstart
jetty-alpn-server
jetty-security
jetty-io
jetty-osgi-alpn
jetty-http2-http-client-transport
jetty-fcgi-server
jetty-infinispan
jetty-continuation
jetty-osgi-boot-jsp
jetty-osgi-boot
jetty-maven-plugin
jetty-websocket-client
jetty-xml
jetty-javax-websocket-client-impl
jetty-javadoc
jetty-jaas
jetty-websocket-servlet
jetty-http-spi
jetty
jetty-util
jetty-rewrite
jetty-websocket-api
jetty-fcgi-client
jetty-plus
jetty-httpservice
jetty-deploy
jetty-servlet
jetty-spring
jetty-javax-websocket-server-impl
jetty-servlets
jetty-jndi
jetty-http2-client
jetty-project
jetty-nosql
jetty-ant
rh-eclipse-jetty (Red Hat package)
openstack-ironic (Red Hat package)
watsonx.data
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Storage Scale System
IBM InfoSphere Information Server
Vue PACS
Contrail Networking
How to mitigate CVE-2021-28165
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-32
AMQ Streams - addressed in versions 1.6.4, 1.8.0
IBM Process Mining - update to 1.12.0.4
Jenkins LTS - update to 2.277.3
Jenkins - update to 2.286
IBM Analytic Accelerator Framework for Communication Service Providers - update to 3.6.0.12.0
Red Hat OpenShift Container Platform - addressed in versions 4.7.11, 4.7.12
Crowd Server - addressed in versions 5.0.11, 5.1.9, 5.2.4
Crowd Data Center - addressed in versions 5.0.11, 5.1.9, 5.2.4
Rational Change - update to 5.3.2.5
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.3.3 Fix Pack 12, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4, 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
AMQ Broker - addressed in versions 7.8.2, 7.9.0
Zimbra Collaboration - addressed in versions 8.8.15 Patch 32, 9.0.0 Patch 25
Jira Software Server - addressed in versions 8.20.27, 9.10.2, 9.11.1
Jira Software Data Center - addressed in versions 8.20.27, 9.10.2, 9.11.1
IBM Customer and Network Analytics for Communications Service Providers and Datasets - update to 9.6.0.12.3
Oracle REST Data Services - addressed in versions 21.2.0, 21.3
Siebel CRM End User - update to 25.7
runc (Red Hat package) - addressed in versions 1.0.0-95.rhaos4.8.gitcd80260.el7, 1.0.0-95.rhaos4.8.gitcd80260.el8
Netcool Operations Insight - update to 1.6.7
Red Hat Integration Camel-K - update to 1.8
cri-tools (Red Hat package) - addressed in versions 1.20.0-2.el7, 1.20.0-2.el8
cri-o (Red Hat package) - addressed in versions 1.20.2-11.rhaos4.7.git704b03d.el7, 1.20.2-11.rhaos4.7.git704b03d.el8
watsonx.data - update to 2.0.1
ignition (Red Hat package) - update to 2.9.0-3.rhaos4.7.git1d56dc8.el8
IBM MaaS360 Mobile Enterprise Gateway - update to 2.106.500
jenkins (Red Hat package) - update to 2.277.3.1620393611-1.el8
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
openshift-ansible (Red Hat package) - update to 4.7.0-202105111743.p0.git.e1b19c2.el7
openshift-kuryr (Red Hat package) - update to 4.7.0-202105111743.p0.git.36c2cdd.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.7.0-202105111743.p0.git.39cfc66.el8
openshift (Red Hat package) - addressed in versions 4.7.0-202105111743.p0.git.75370d3.el7, 4.7.0-202105111743.p0.git.75370d3.el8
openshift-clients (Red Hat package) - addressed in versions 4.7.0-202105111743.p0.git.95881af.el7, 4.7.0-202105111743.p0.git.95881af.el8
IBM Storage Scale System - update to 5.1.9.0
IBM Enterprise Records - update to 5.2.1.8 IF002
Datastax Enterprise with IBM - addressed in versions 6.8.63, 6.9.20
Engineering Lifecycle Management - Jazz Foundation - addressed in versions 7.0.3 iFix018, 7.1.0 iFix005
IBM Security Directory Suite - update to 8.0.1.21
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Spectrum Protect Storage Agent - update to 8.1.19
jetty-start - update to 9.4.15-7
jetty-unixsocket - update to 9.4.15-7
jetty-server - update to 9.4.15-7
jetty-jmx - update to 9.4.15-7
jetty-cdi - update to 9.4.15-7
jetty-proxy - update to 9.4.15-7
jetty-http2-common - update to 9.4.15-7
jetty-webapp - update to 9.4.15-7
jetty-websocket-common - update to 9.4.15-7
jetty-osgi-boot-warurl - update to 9.4.15-7
jetty-jstl - update to 9.4.15-7
jetty-util-ajax - update to 9.4.15-7
jetty-http - update to 9.4.15-7
jetty-websocket-server - update to 9.4.15-7
jetty-jspc-maven-plugin - update to 9.4.15-7
jetty-http2-hpack - update to 9.4.15-7
jetty-annotations - update to 9.4.15-7
jetty-jsp - update to 9.4.15-7
jetty-alpn-client - update to 9.4.15-7
jetty-client - update to 9.4.15-7
jetty-http2-server - update to 9.4.15-7
jetty-jaspi - update to 9.4.15-7
jetty-quickstart - update to 9.4.15-7
jetty-alpn-server - update to 9.4.15-7
jetty-security - update to 9.4.15-7
jetty-io - update to 9.4.15-7
jetty-osgi-alpn - update to 9.4.15-7
jetty-http2-http-client-transport - update to 9.4.15-7
jetty-fcgi-server - update to 9.4.15-7
jetty-infinispan - update to 9.4.15-7
jetty-continuation - update to 9.4.15-7
jetty-osgi-boot-jsp - update to 9.4.15-7
jetty-osgi-boot - update to 9.4.15-7
jetty-maven-plugin - update to 9.4.15-7
jetty-websocket-client - update to 9.4.15-7
jetty-xml - update to 9.4.15-7
jetty-javax-websocket-client-impl - update to 9.4.15-7
jetty-javadoc - update to 9.4.15-7
jetty-jaas - update to 9.4.15-7
jetty-websocket-servlet - update to 9.4.15-7
jetty-http-spi - update to 9.4.15-7
jetty - update to 9.4.15-7
jetty-util - update to 9.4.15-7
jetty-rewrite - update to 9.4.15-7
jetty-websocket-api - update to 9.4.15-7
jetty-fcgi-client - update to 9.4.15-7
jetty-plus - update to 9.4.15-7
jetty-httpservice - update to 9.4.15-7
jetty-deploy - update to 9.4.15-7
jetty-servlet - update to 9.4.15-7
jetty-spring - update to 9.4.15-7
jetty-javax-websocket-server-impl - update to 9.4.15-7
jetty-servlets - update to 9.4.15-7
jetty-jndi - update to 9.4.15-7
jetty-http2-client - update to 9.4.15-7
jetty-project - update to 9.4.15-7
jetty-nosql - update to 9.4.15-7
jetty-ant - update to 9.4.15-7
jetty - addressed in versions 9.4.40-1.fc32, 9.4.40-1.fc33, 9.4.40-1.fc34
rh-eclipse-jetty (Red Hat package) - update to 9.4.40-1.1.el7_9
jetty-io - update to 9.4.42-3.9.1
jetty-http - update to 9.4.42-3.9.1
jetty-server - update to 9.4.42-3.9.1
jetty-servlet - update to 9.4.42-3.9.1
jetty-util - update to 9.4.42-3.9.1
jetty-util-ajax - update to 9.4.42-3.9.1
jetty-security - update to 9.4.42-3.9.1
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
Dell Security Management Server - update to 11.1.1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
Vue PACS - update to 12.2.8.410
openstack-ironic (Red Hat package) - update to 16.0.4-0.20210510131210.6787142.el8
Dell NetWorker Virtual Edition - addressed in versions 19.8.0.4, 19.9.0.2
Contrail Networking - update to 2011.L5
External References
Related Security Bulletins
- Multiple vulnerabilities in Jetty
- Denial of service in Jenkins and Jenkins LTS
- Red Hat Developer Tools update for rh-eclipse-jetty
- Red Hat AMQ Streams update for jetty
- Multiple vulnerabilities in OpenShift Container Platform
- Multiple vulnerabilities in OpenShift Container Platform
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Red Hat AMQ Streams
- Multiple vulnerabilities in Red Hat AMQ Broker
- Denial of service in Traffix SDC Bash (Jetty server)
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Oracle REST Data Services
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in IBM MaaS360 Mobile Enterprise Gateway
- SUSE update for jetty-minimal
- Multiple vulnerabilities in IBM Sterling Connect:Direct Browser User Interface
- Multiple vulnerabilities in IBM Rational Performance Tester
- Multiple vulnerabilities in Zimbra Collaboration
- Multiple vulnerabilities in IBM QRadar SIEM
- Resource exhaustion in Oracle REST Data Services
- Multiple vulnerabilities in Oracle Autovue for Agile Product Lifecycle Management
- Multiple vulnerabilities in Red Hat Integration Camel-K
- Multiple vulnerabilities in IBM Rational Change
- Multiple vulnerabilities in Juniper Networks Contrail Networking
- Resource exhaustion in Oracle Communications Converged Application Server - Service Controller
- Multiple vulnerabilities in Dell Security Management Server
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Denial of service in IBM Enterprise Records
- Resource exhaustion in IBM Process Mining
- Resource exhaustion in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM App Connect Enterprise Toolkit and the IBM Integration Bus Toolkit
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Analytic Accelerator Framework for Communication Service Providers & IBM Customer and Network Analytics
- Multiple vulnerabilities in Netcool Operations Insight
- Resource exhaustion in Oracle Unified Directory
- Multiple vulnerabilities in Dell NetWorker Virtual Edition
- Jira Software Data Center and Server update for Jetty
- Multiple vulnerabilities in IBM Storage Scale
- Multiple vulnerabilities in IBM Application Performance Management
- openEuler 20.03 LTS SP1 update for jetty
- Multiple vulnerabilities in IBM Security Directory Integrator
- Crowd Data Center and Server update for jetty-io
- Multiple vulnerabilities in Philips Vue PACS
- Multiple vulnerabilities in IBM Security Verify Directory
- Resource exhaustion in IBM watsonx.data
- Multiple vulnerabilities in IBM Security Directory Suite
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.7
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.7
- Fedora 34 update for jetty
- Fedora 33 update for jetty
- Fedora 32 update for jetty
- Multiple vulnerabilities in IBM Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in Siebel CRM End User
- Multiple vulnerabilities in IBM Engineering Lifecycle Management - Jazz Foundation
- Multiple vulnerabilities in IBM DataStax Enterprise