Input validation error in Jetty - CVE-2021-28164
Published: April 1, 2021 / Updated: November 25, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive informatoin.
The vulnerability exists due to insufficient validation of user-supplied input when processing special characters, passed via URI. A remote attacker can use %2e or %2e%2e segments to access protected resources within the WEB-INF directory.
Example:
http://[host]/context/%2e/WEB-INF/web.xml
Affected software
Red Hat Developer Tools
Sterling Connect:Direct Browser User Interface
Rational Change
AMQ Streams
AMQ Broker
Fuse
IBM Analytic Accelerator Framework for Communication Service Providers
IBM Qradar SIEM
Rational Performance Tester
Oracle Banking Digital Experience
IBM Customer and Network Analytics for Communications Service Providers and Datasets
Oracle Banking APIs
Netcool Operations Insight
Red Hat Integration Camel-K
IBM MaaS360 Mobile Enterprise Gateway
Dell NetWorker Virtual Edition
SUSE Linux Enterprise Module for Development Tools
Anolis OS
Fedora
Dell EMC Storage Monitoring and Reporting (SMR)
jetty
rh-eclipse-jetty (Red Hat package)
jetty-server
jetty-http
jetty-io
jetty-util-ajax
jetty-util
jetty-servlet
jetty-security
jetty-xml
jetty-webapp
jetty-jmx
jetty-javadoc
jetty-jaas
jetty-continuation
jetty-client
IBM InfoSphere Information Server
How to mitigate CVE-2021-28164
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-32
AMQ Streams - addressed in versions 1.6.4, 1.8.0
IBM Analytic Accelerator Framework for Communication Service Providers - update to 3.6.0.12.0
Rational Change - update to 5.3.2.5
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 12, 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
AMQ Broker - addressed in versions 7.8.2, 7.9.0
IBM Customer and Network Analytics for Communications Service Providers and Datasets - update to 9.6.0.12.3
Netcool Operations Insight - update to 1.6.7
Red Hat Integration Camel-K - update to 1.8
IBM MaaS360 Mobile Enterprise Gateway - update to 2.106.500
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
Fuse - update to 7.10.0
jetty - addressed in versions 9.4.40-1.fc32, 9.4.40-1.fc33, 9.4.40-1.fc34
rh-eclipse-jetty (Red Hat package) - update to 9.4.40-1.1.el7_9
jetty-server - update to 9.4.42-3.9.1
jetty-http - update to 9.4.42-3.9.1
jetty-io - update to 9.4.42-3.9.1
jetty-util-ajax - update to 9.4.42-3.9.1
jetty-util - update to 9.4.42-3.9.1
jetty-servlet - update to 9.4.42-3.9.1
jetty-security - update to 9.4.42-3.9.1
jetty-xml - update to 9.4.43-1
jetty-webapp - update to 9.4.43-1
jetty-util-ajax - update to 9.4.43-1
jetty-util - update to 9.4.43-1
jetty-servlet - update to 9.4.43-1
jetty-server - update to 9.4.43-1
jetty-security - update to 9.4.43-1
jetty-jmx - update to 9.4.43-1
jetty-javadoc - update to 9.4.43-1
jetty-jaas - update to 9.4.43-1
jetty-io - update to 9.4.43-1
jetty-http - update to 9.4.43-1
jetty-continuation - update to 9.4.43-1
jetty-client - update to 9.4.43-1
jetty - update to 9.4.43-1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
Dell NetWorker Virtual Edition - addressed in versions 19.8.0.4, 19.9.0.2
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Jetty
- Red Hat Developer Tools update for rh-eclipse-jetty
- Red Hat AMQ Streams update for jetty
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Red Hat AMQ Streams
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Oracle Banking Digital Experience
- Multiple vulnerabilities in Oracle Banking APIs
- Multiple vulnerabilities in IBM MaaS360 Mobile Enterprise Gateway
- SUSE update for jetty-minimal
- Multiple vulnerabilities in IBM Sterling Connect:Direct Browser User Interface
- Multiple vulnerabilities in IBM Rational Performance Tester
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat Integration Camel-K
- Multiple vulnerabilities in IBM Rational Change
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Analytic Accelerator Framework for Communication Service Providers & IBM Customer and Network Analytics
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Dell NetWorker Virtual Edition
- Multiple vulnerabilities in Fuse 7.10
- Fedora 34 update for jetty
- Fedora 33 update for jetty
- Fedora 32 update for jetty
- Anolis OS update for jetty