Improper input validation in Oracle Java SE - CVE-2021-2432
Published: July 20, 2021 / Updated: June 24, 2022
Vulnerability identifier: #VU55059
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-2432
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The vulnerability exists due to improper input validation within the JNDI component in Java SE. A remote non-authenticated attacker can exploit this vulnerability to perform service disruption.
Affected software
Oracle Java SE
Engineering Lifecycle Management
IBM Java SDK
SecurID Governance and Lifecycle
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Transformation Advisor
Content Collector for File Systems
Content Collector for Microsoft SharePoint
Content Collector for Email
Content Collector for IBM Connections
Engineering Lifecycle Optimization - Engineering Insights
Engineering Workflow Management
IBM Rational Build Forge
CICS Transaction Gateway
IBM Tivoli Monitoring
Tivoli Composite Application Manager for Transactions
Dell EMC Data Protection Search
Virtualization Engine TS7700 3957-VEC
Virtualization Engine TS7700 3957-VED
RSA Identity Governance and Lifecycle
Gentoo Linux
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
IBM AIX
IBM i
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
IBM Engineering Requirements Quality Assistant
IBM Kenexa LMS
IBM WebSphere Application Server Patterns
IBM Engineering Systems Design Rhapsody
IBM Engineering Requirements Management DOORS Next
Engineering Test Management
IBM Engineering Lifecycle Optimization - Publishing
IBM Watson Compare and Comply for IBM Cloud Pak for Data
Connectrix (Brocade)
Dell EMC NetWorker Runtime Environment (NRE)
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
Dell EMC PowerProtect Data Protection
Brocade SANnav
Cloud Pak for Security (CP4S)
IBM Cognos Controller
java-1.7.1-ibm (Red Hat package)
java-1_7_0-ibm-plugin
java-1_7_0-ibm-jdbc
java-1_7_0-ibm-devel
java-1_7_0-ibm-alsa
java-1_7_0-ibm
java-1_7_0-openjdk-headless
java-1_7_0-openjdk-headless-debuginfo
java-1_7_0-openjdk-devel-debuginfo
java-1_7_0-openjdk-devel
java-1_7_0-openjdk-demo-debuginfo
java-1_7_0-openjdk-demo
java-1_7_0-openjdk-debugsource
java-1_7_0-openjdk-debuginfo
java-1_7_0-openjdk
java-1_7_1-ibm-alsa
java-1_7_1-ibm-plugin
java-1_7_1-ibm-jdbc
java-1_7_1-ibm-devel
java-1_7_1-ibm
HPE SANnav Management Software
IBM VIOS
Solutions Enabler Virtual Appliance
Engineering Lifecycle Management
IBM Java SDK
SecurID Governance and Lifecycle
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Transformation Advisor
Content Collector for File Systems
Content Collector for Microsoft SharePoint
Content Collector for Email
Content Collector for IBM Connections
Engineering Lifecycle Optimization - Engineering Insights
Engineering Workflow Management
IBM Rational Build Forge
CICS Transaction Gateway
IBM Tivoli Monitoring
Tivoli Composite Application Manager for Transactions
Dell EMC Data Protection Search
Virtualization Engine TS7700 3957-VEC
Virtualization Engine TS7700 3957-VED
RSA Identity Governance and Lifecycle
Gentoo Linux
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
IBM AIX
IBM i
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
IBM Engineering Requirements Quality Assistant
IBM Kenexa LMS
IBM WebSphere Application Server Patterns
IBM Engineering Systems Design Rhapsody
IBM Engineering Requirements Management DOORS Next
Engineering Test Management
IBM Engineering Lifecycle Optimization - Publishing
IBM Watson Compare and Comply for IBM Cloud Pak for Data
Connectrix (Brocade)
Dell EMC NetWorker Runtime Environment (NRE)
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
Dell EMC PowerProtect Data Protection
Brocade SANnav
Cloud Pak for Security (CP4S)
IBM Cognos Controller
java-1.7.1-ibm (Red Hat package)
java-1_7_0-ibm-plugin
java-1_7_0-ibm-jdbc
java-1_7_0-ibm-devel
java-1_7_0-ibm-alsa
java-1_7_0-ibm
java-1_7_0-openjdk-headless
java-1_7_0-openjdk-headless-debuginfo
java-1_7_0-openjdk-devel-debuginfo
java-1_7_0-openjdk-devel
java-1_7_0-openjdk-demo-debuginfo
java-1_7_0-openjdk-demo
java-1_7_0-openjdk-debugsource
java-1_7_0-openjdk-debuginfo
java-1_7_0-openjdk
java-1_7_1-ibm-alsa
java-1_7_1-ibm-plugin
java-1_7_1-ibm-jdbc
java-1_7_1-ibm-devel
java-1_7_1-ibm
HPE SANnav Management Software
IBM VIOS
Solutions Enabler Virtual Appliance
How to mitigate CVE-2021-2432
Install updates from vendor's website.
Virtualization Engine TS7700 3957-VEC - addressed in versions 8.50.2.6, 8.51.1.26
Virtualization Engine TS7700 3957-VED - addressed in versions 8.50.2.6, 8.51.1.26
Brocade SANnav - addressed in versions 2.1.1.8, 2.2.0.2
Netcool Operations Insight - update to 1.6.5
Cloud Pak for Security (CP4S) - update to 1.8.0.0
java-1.7.1-ibm (Red Hat package) - update to 1.7.1.4.90-1jpp.1.el7
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 2.2.1-patch-5, 4.0.3
HPE SANnav Management Software - addressed in versions 2.1.1.8, 2.2.0.2
IBM Cloud Transformation Advisor - update to 2.5.0
IBM Rational Build Forge - update to 8.0.0.21
IBM Watson Compare and Comply for IBM Cloud Pak for Data - update to 1.1.13
java-1_7_0-ibm-plugin - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-jdbc - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-devel - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-alsa - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-openjdk-headless - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-headless-debuginfo - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-devel-debuginfo - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-devel - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-demo-debuginfo - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-demo - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-debugsource - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-debuginfo - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk - update to 1.7.0.311-43.50.2
java-1_7_1-ibm-alsa - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm-plugin - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm-jdbc - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm-devel - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
Connectrix (Brocade) - addressed in versions 2.1.1.8, 2.2.0.2
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 9
IBM Java SDK - addressed in versions 7.0-10.90, 7.1-4.90, 8.0-6.35
Tivoli Composite Application Manager for Transactions - update to 7.4.0.1-TIV-CAMRT-IF0056
Dell EMC NetWorker Runtime Environment (NRE) - update to 8.0.10
Solutions Enabler - addressed in versions 9.1.0.17, 9.2.2.0
Solutions Enabler Virtual Appliance - addressed in versions 9.1.0.17, 9.2.2.0
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.28, 9.2.2.2
Unisphere for PowerMax - addressed in versions 9.1.0.28, 9.2.2.2
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
Dell EMC PowerProtect Data Protection - update to 19.5.1
Dell EMC Data Protection Search - update to 19.5.1
Virtualization Engine TS7700 3957-VED - addressed in versions 8.50.2.6, 8.51.1.26
Brocade SANnav - addressed in versions 2.1.1.8, 2.2.0.2
Netcool Operations Insight - update to 1.6.5
Cloud Pak for Security (CP4S) - update to 1.8.0.0
java-1.7.1-ibm (Red Hat package) - update to 1.7.1.4.90-1jpp.1.el7
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 2.2.1-patch-5, 4.0.3
HPE SANnav Management Software - addressed in versions 2.1.1.8, 2.2.0.2
IBM Cloud Transformation Advisor - update to 2.5.0
IBM Rational Build Forge - update to 8.0.0.21
IBM Watson Compare and Comply for IBM Cloud Pak for Data - update to 1.1.13
java-1_7_0-ibm-plugin - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-jdbc - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-devel - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-alsa - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-openjdk-headless - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-headless-debuginfo - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-devel-debuginfo - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-devel - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-demo-debuginfo - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-demo - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-debugsource - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk-debuginfo - update to 1.7.0.311-43.50.2
java-1_7_0-openjdk - update to 1.7.0.311-43.50.2
java-1_7_1-ibm-alsa - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm-plugin - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm-jdbc - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm-devel - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
Connectrix (Brocade) - addressed in versions 2.1.1.8, 2.2.0.2
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 9
IBM Java SDK - addressed in versions 7.0-10.90, 7.1-4.90, 8.0-6.35
Tivoli Composite Application Manager for Transactions - update to 7.4.0.1-TIV-CAMRT-IF0056
Dell EMC NetWorker Runtime Environment (NRE) - update to 8.0.10
Solutions Enabler - addressed in versions 9.1.0.17, 9.2.2.0
Solutions Enabler Virtual Appliance - addressed in versions 9.1.0.17, 9.2.2.0
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.28, 9.2.2.2
Unisphere for PowerMax - addressed in versions 9.1.0.28, 9.2.2.2
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
Dell EMC PowerProtect Data Protection - update to 19.5.1
Dell EMC Data Protection Search - update to 19.5.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Java SE
- Red Hat Enterprise Linux 7 Supplementary update for java-1.7.1-ibm
- IBM AIX update for Java SDK
- IBM VIOS update for Java SDK
- Multiple vulnerabilities in IBM Watson Discovery for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Rational Build Forge
- SUSE update for java-1_7_0-openjdk
- Multiple vulnerabilities in Brocade SANnav
- Multiple vulnerabilities in HPE SANnav Management Software
- Multiple vulnerabilities in IBM Tivoli Composite Application Manager
- Multiple Vulnerabilities in IBM Virtualization Engine TS7700
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in IBM Watson Compare and Comply for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM i
- Multiple vulnerabilities in IBM Content Collector for Email, Content Collector for File Systems, Content Collector for Microsoft SharePoint and Content Collector for IBM Connections
- Gentoo update for OpenJDK
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Kenexa LMS On Premise
- Multiple vulnerabilities in IBM CICS Transaction Gateway
- Multiple vulnerabilities in IBM Java SDK
- Multiple vulnerabilities in IBM WebSphere Application Server Patterns
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Dell Connectrix
- Multiple vulnerabilities in IBM Continuous Engineering products based on IBM Jazz Technology
- Multiple vulnerabilities in Dell EMC Data Protection Search and Dell EMC PowerProtect Data Protection
- Multiple vulnerabilities in Dell EMC NetWorker Runtime Environment (NRE)
- Multiple vulnerabilities in Dell EMC Unisphere for PowerMax and Dell EMC Solutions Enabler
- IBM Tivoli Monitoring update for Java
- SUSE update for java-1_7_1-ibm
- SUSE update for java-1_7_1-ibm
- SUSE update for java-1_7_1-ibm
- Multiple vulnerabilities in IBM Cognos Controller
- Gentoo update for IcedTea
- RSA Governance and Lifecycle update for Oracle Databse