Information disclosure in Jersey - CVE-2021-28168
Published: April 27, 2021
Vulnerability details
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. A local attacker can gain unauthorized access to sensitive information on the system.
Affected software
AMQ Streams
Oracle WebLogic Server
Oracle Communications Cloud Native Core Unified Data Repository
Oracle Communications Cloud Native Core Policy
IBM Watson Machine Learning Accelerator
Oracle Business Intelligence Enterprise Edition
Oracle Financial Services Analytical Applications Infrastructure
Cloudera Data Platform Private Cloud Base for IBM
openEuler
Netcool Operations Insight
IBM Sterling Partner Engagement Manager
jersey
jersey-javadoc
jersey-test-framework
How to mitigate CVE-2021-28168
AMQ Streams - update to 1.8.0
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
Netcool Operations Insight - update to 1.6.7
jersey - addressed in versions 2.28-2, 2.29.1-2
jersey-javadoc - addressed in versions 2.28-2, 2.29.1-2
jersey-test-framework - addressed in versions 2.28-2, 2.29.1-2
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.8, 6.2.0.6, 6.2.1.3, 6.2.1.8, 6.2.2.1
External References
Related Security Bulletins
- Information disclosure in Eclipse Jersey
- Multiple vulnerabilities in Red Hat AMQ Streams
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Unified Data Repository
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Information disclosure in IBM Sterling Partner Engagement Manager
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Watson Machine Learning Accelerator on Cloud Pak for Data
- openEuler 20.03 LTS SP1 update for jersey
- openEuler 22.03 LTS update for jersey
- openEuler 22.03 LTS SP1 update for jersey
- openEuler 22.03 LTS SP2 update for jersey
- openEuler 22.03 LTS SP3 update for jersey
- Multiple vulnerabilities in Cloudera Data Platform Private Cloud Base with IBM (CDP)
- Multiple vulnerabilities in Oracle Financial Services Analytical Applications Infrastructure
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition