Cross-site scripting in CKEditor - CVE-2021-37695

 

Cross-site scripting in CKEditor - CVE-2021-37695

Published: August 16, 2021


Vulnerability identifier: #VU55859
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2021-37695
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in the Fake Objects plugin. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

CKEditor
Oracle Banking Party Management
IBM Sterling B2B Integrator
Engineering Workflow Management
Fedora
Ubuntu
Jazz Foundation
Oracle Financial Services Analytical Applications Infrastructure
IBM Engineering Requirements Management DOORS Next
Oracle Siebel CRM
Engineering Test Management
PeopleSoft Enterprise PeopleTools
Oracle Commerce Merchandising
Oracle Commerce Guided Search
Oracle Application Express
ckeditor (Ubuntu package)
ckeditor

How to mitigate CVE-2021-37695

Install updates from vendor's website.

CKEditor - update to 4.16.2
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.6, 6.1.1.2, 6.1.2.1, 6.1.2.6, 6.2.0.3
Jazz Foundation - addressed in versions 7.0.2.0.35, 7.0.3.0.17, 7.1.0.0.4
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Oracle Siebel CRM - update to 21.2
Oracle Application Express - update to 21.1.4
ckeditor (Ubuntu package) - addressed in versions 4.5.7+dfsg-2ubuntu0.18.04.1, 4.12.1+dfsg-1ubuntu0.1, 4.16.0+dfsg-2ubuntu0.1
ckeditor - addressed in versions 4.16.2-1.el7, 4.16.2-1.fc33, 4.16.2-1.fc34, 4.16.2-1.fc35
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021
Engineering Test Management - addressed in versions 7.0.1.0.23, 7.0.2.0.24

External References

Related Security Bulletins