Information disclosure in Jersey - CVE-2021-28168

 

Information disclosure in Jersey - CVE-2021-28168

Published: April 27, 2021


Vulnerability identifier: #VU52651
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28168
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. A local attacker can gain unauthorized access to sensitive information on the system.


Affected software

Jersey
AMQ Streams
Oracle WebLogic Server
Oracle Communications Cloud Native Core Unified Data Repository
Oracle Communications Cloud Native Core Policy
IBM Watson Machine Learning Accelerator
Oracle Business Intelligence Enterprise Edition
Oracle Financial Services Analytical Applications Infrastructure
Cloudera Data Platform Private Cloud Base for IBM
openEuler
Netcool Operations Insight
IBM Sterling Partner Engagement Manager
jersey
jersey-javadoc
jersey-test-framework

How to mitigate CVE-2021-28168

Install updates from vendor's website.

Jersey - update to 3.0.2
AMQ Streams - update to 1.8.0
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
Netcool Operations Insight - update to 1.6.7
jersey - addressed in versions 2.28-2, 2.29.1-2
jersey-javadoc - addressed in versions 2.28-2, 2.29.1-2
jersey-test-framework - addressed in versions 2.28-2, 2.29.1-2
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.8, 6.2.0.6, 6.2.1.3, 6.2.1.8, 6.2.2.1

External References

Related Security Bulletins