Input validation error in xmldom - CVE-2021-32796

 

Input validation error in xmldom - CVE-2021-32796

Published: August 3, 2021


Vulnerability identifier: #VU55534
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32796
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromsie the target system.

The vulnerability exists due to the affected software does not correctly escape special characters when serializing elements removed from their ancestor. A remote attacker can cause unexpected syntactic changes during XML processing in some downstream applications.


Affected software

xmldom
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Knowledge Catalog Premium Cartridge
Data Product Hub
Maximo Application Suite - Visual Inspection Component
IBM Spectrum Control
IBM App Connect Enterprise

How to mitigate CVE-2021-32796

Install updates from vendor's website.

xmldom - update to 0.7.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.0.1
Knowledge Catalog Premium Cartridge - update to 5.2
Data Product Hub - update to 5.2.1
IBM Spectrum Control - update to 5.4.13.2
Maximo Application Suite - Visual Inspection Component - update to 9.1.1
IBM App Connect Enterprise - addressed in versions 12.0.12.17, 13.0.4.1

External References

Related Security Bulletins