Input validation error in Apache CXF - CVE-2021-22696

 

Input validation error in Apache CXF - CVE-2021-22696

Published: April 6, 2021


Vulnerability identifier: #VU51939
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22696
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper validation of "request_uri" parameter by the OAuth 2 authorization service. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Apache CXF
JBoss Web Server
Dell Secure Connect Gateway
IBM Sterling B2B Integrator
IBM Security Verify Governance
IBM Qradar SIEM
IBM Security Guardium
IBM Tivoli Network Manager (ITNM)
Fuse

How to mitigate CVE-2021-22696

Install updates from vendor's website.

Apache CXF - addressed in versions 3.3.10, 3.4.3
JBoss Web Server - update to 5.7.0
Dell Secure Connect Gateway - update to 5.14.00.10
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.13
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
Fuse - update to 7.10.0
IBM Security Verify Governance - update to 10.0.1.0.5

External References

Related Security Bulletins