Input validation error in Apache CXF - CVE-2021-22696
Published: April 6, 2021
Vulnerability identifier: #VU51939
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22696
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of "request_uri" parameter by the OAuth 2 authorization service. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Apache CXF
JBoss Web Server
Dell Secure Connect Gateway
IBM Sterling B2B Integrator
IBM Security Verify Governance
IBM Qradar SIEM
IBM Security Guardium
IBM Tivoli Network Manager (ITNM)
Fuse
JBoss Web Server
Dell Secure Connect Gateway
IBM Sterling B2B Integrator
IBM Security Verify Governance
IBM Qradar SIEM
IBM Security Guardium
IBM Tivoli Network Manager (ITNM)
Fuse
How to mitigate CVE-2021-22696
Install updates from vendor's website.
Apache CXF - addressed in versions 3.3.10, 3.4.3
JBoss Web Server - update to 5.7.0
Dell Secure Connect Gateway - update to 5.14.00.10
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.13
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
Fuse - update to 7.10.0
IBM Security Verify Governance - update to 10.0.1.0.5
JBoss Web Server - update to 5.7.0
Dell Secure Connect Gateway - update to 5.14.00.10
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.13
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
Fuse - update to 7.10.0
IBM Security Verify Governance - update to 10.0.1.0.5
External References
- http://www.openwall.com/lists/oss-security/2021/04/02/2
- https://cxf.apache.org/security-advisories.data/CVE-2021-22696.txt.asc
- https://lists.apache.org/thread.html/r6445001cc5f9a2bb1e6316993753306e054bdd1d702656b7cbe59045@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/r8651c06212c56294a1c0ea61a5ad7790c06502209c03f05c0c7c9914@%3Cdev.cxf.apache.org%3E
- https://lists.apache.org/thread.html/r8651c06212c56294a1c0ea61a5ad7790c06502209c03f05c0c7c9914@%3Cusers.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4@%3Ccommits.cxf.apache.org%3E
Related Security Bulletins
- Denial of service in Apache CXF
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Denial of service in IBM Tivoli Network Manager IP Edition
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Multiple vulnerabilities in Fuse 7.10