Resource exhaustion in Apache CXF - CVE-2021-30468

 

Resource exhaustion in Apache CXF - CVE-2021-30468

Published: August 20, 2021


Vulnerability identifier: #VU56019
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30468
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in the JsonMapObjectReaderWriter. A remote attacker can trigger resource exhaustion by submitting a malformed JSON to a web service and perform a denial of service (DoS) attack.


Affected software

Apache CXF
JBoss Web Server
Dell Secure Connect Gateway
Oracle Communications Diameter Intelligence Hub
IBM Sterling B2B Integrator
IBM Security Verify Governance
Oracle Business Intelligence Enterprise Edition
Oracle Communications Instant Messaging Server
IBM Security Guardium
IBM TRIRIGA Application Platform
Fuse

How to mitigate CVE-2021-30468

Install updates from vendor's website.

Apache CXF - addressed in versions 3.3.11, 3.4.4
JBoss Web Server - update to 5.7.0
Dell Secure Connect Gateway - update to 5.14.00.10
IBM TRIRIGA Application Platform - addressed in versions 3.6.1.3, 3.7.0.1, 3.8.0.1, 4.0.2, 4.1.1
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
Fuse - update to 7.10.0
IBM Security Verify Governance - update to 10.0.1.0.5

External References

Related Security Bulletins