Resource exhaustion in Apache CXF - CVE-2021-30468
Published: August 20, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the JsonMapObjectReaderWriter. A remote attacker can trigger resource exhaustion by submitting a malformed JSON to a web service and perform a denial of service (DoS) attack.
Affected software
JBoss Web Server
Dell Secure Connect Gateway
Oracle Communications Diameter Intelligence Hub
IBM Sterling B2B Integrator
IBM Security Verify Governance
Oracle Business Intelligence Enterprise Edition
Oracle Communications Instant Messaging Server
IBM Security Guardium
IBM TRIRIGA Application Platform
Fuse
How to mitigate CVE-2021-30468
JBoss Web Server - update to 5.7.0
Dell Secure Connect Gateway - update to 5.14.00.10
IBM TRIRIGA Application Platform - addressed in versions 3.6.1.3, 3.7.0.1, 3.8.0.1, 4.0.2, 4.1.1
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
Fuse - update to 7.10.0
IBM Security Verify Governance - update to 10.0.1.0.5
External References
- http://cxf.apache.org/security-advisories.data/CVE-2021-30468.txt.asc
- https://lists.apache.org/thread.html/r4a4b6bc0520b69c18d2a59daa6af84ae49f0c22164dccb8538794459@%3Cdev.cxf.apache.org%3E
- https://lists.apache.org/thread.html/r4a4b6bc0520b69c18d2a59daa6af84ae49f0c22164dccb8538794459@%3Cusers.cxf.apache.org%3E
- https://lists.apache.org/thread.html/r4a4b6bc0520b69c18d2a59daa6af84ae49f0c22164dccb8538794459@%3Cannounce.apache.org%3E
- http://www.openwall.com/lists/oss-security/2021/06/16/2
Related Security Bulletins
- Denial of service in Apache CXF
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Oracle Communications Diameter Intelligence Hub
- Denial of service in IBM TRIRIGA Application Platform
- Multiple vulnerabilities in Oracle Communications Messaging Server
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Multiple vulnerabilities in Fuse 7.10