Improper input validation in PeopleSoft Enterprise PeopleTools - CVE-2021-27568

 

Improper input validation in PeopleSoft Enterprise PeopleTools - CVE-2021-27568

Published: July 27, 2021


Vulnerability identifier: #VU55372
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27568
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read data or crash the application.

The vulnerability exists due to improper input validation within the REST Services (netplex json-smart-v1) component in PeopleSoft Enterprise PeopleTools. A remote non-authenticated attacker can exploit this vulnerability to read data or crash the application.


Affected software

PeopleSoft Enterprise PeopleTools
AMQ Streams
Oracle WebLogic Server
Fuse
Oracle Communications Cloud Native Core Policy
OSS Support Tools
Oracle Utilities Framework
Oracle Business Intelligence Enterprise Edition
IBM Cloud Pak for Watson AIOps
IBM Engineering Lifecycle Optimization - Publishing
IBM Engineering Requirements Management DOORS Next
Robotic Process Automation for Cloud Pak
IBM Security Verify Access
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2021-27568

Install updates from vendor's website.

AMQ Streams - update to 1.8.0
OSS Support Tools - update to 2.12.42
IBM Cloud Pak for Watson AIOps - update to 3.7.1
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.1.23, 7.0.2.25
Fuse - update to 7.10.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
Robotic Process Automation for Cloud Pak - update to 21.0.7

External References

Related Security Bulletins