Cross-site scripting in CKEditor - CVE-2021-37695
Published: August 16, 2021
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the Fake Objects plugin. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Oracle Banking Party Management
IBM Sterling B2B Integrator
Engineering Workflow Management
Fedora
Ubuntu
Jazz Foundation
Oracle Financial Services Analytical Applications Infrastructure
IBM Engineering Requirements Management DOORS Next
Oracle Siebel CRM
Engineering Test Management
PeopleSoft Enterprise PeopleTools
Oracle Commerce Merchandising
Oracle Commerce Guided Search
Oracle Application Express
ckeditor (Ubuntu package)
ckeditor
How to mitigate CVE-2021-37695
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.6, 6.1.1.2, 6.1.2.1, 6.1.2.6, 6.2.0.3
Jazz Foundation - addressed in versions 7.0.2.0.35, 7.0.3.0.17, 7.1.0.0.4
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Oracle Siebel CRM - update to 21.2
Oracle Application Express - update to 21.1.4
ckeditor (Ubuntu package) - addressed in versions 4.5.7+dfsg-2ubuntu0.18.04.1, 4.12.1+dfsg-1ubuntu0.1, 4.16.0+dfsg-2ubuntu0.1
ckeditor - addressed in versions 4.16.2-1.el7, 4.16.2-1.fc33, 4.16.2-1.fc34, 4.16.2-1.fc35
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021
Engineering Test Management - addressed in versions 7.0.1.0.23, 7.0.2.0.24
External References
Related Security Bulletins
- Multiple vulnerabilities in CKEditor
- Multiple vulnerabilities in Oracle Application Express
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in Oracle Financial Services Analytical Applications Infrastructure
- Multiple vulnerabilities in Oracle Banking Party Management
- Ubuntu update for ckeditor
- Cross-site scripting in Oracle Commerce Merchandising
- Cross-site scripting in Oracle Commerce Guided Search
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Multiple vulnerabilities in Oracle Siebel CRM
- Multiple vulnerabilities in IBM Engineering Workflow Management (EWM)
- Multiple vulnerabilities in IBM Engineering Test Management (ETM)
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- IBM Sterling B2B Integrator update for CKEditor
- Fedora 34 update for ckeditor
- Fedora 33 update for ckeditor
- Fedora EPEL 7 update for ckeditor
- Fedora 35 update for ckeditor
- Multiple vulnerabilities in IBM Engineering Lifecycle Management - Jazz Foundation