Information disclosure in IBM WebSphere Application Server - CVE-2021-29842
Published: September 16, 2021
Vulnerability identifier: #VU56660
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29842
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output, when the WebSphere Application Server is configured with a federated repository. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
IBM WebSphere Application Server
IBM IoT MessageSight
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM WIoTP MessageGateway
IBM Intelligent Operations Center
IBM Tivoli Monitoring
IBM Tivoli Netcool Impact
IBM Transformation Extender Advanced
IBM Copy Services Manager
IBM Watson Compare and Comply for IBM Cloud Pak for Data
Liberty for Java for IBM Cloud
IBM IoT MessageSight
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM WIoTP MessageGateway
IBM Intelligent Operations Center
IBM Tivoli Monitoring
IBM Tivoli Netcool Impact
IBM Transformation Extender Advanced
IBM Copy Services Manager
IBM Watson Compare and Comply for IBM Cloud Pak for Data
Liberty for Java for IBM Cloud
How to mitigate CVE-2021-29842
Install updates from vendor's website.
IBM WebSphere Application Server - addressed in versions 7.0.0.45 PH38929, 8.0.0.15 PH38929, 8.5.5.20 PH38929, 9.0.5.9 PH38929
IBM Intelligent Operations Center - update to 5.2.3
IBM Copy Services Manager - update to 6.3.2
IBM Tivoli Netcool Impact - update to 7.1.0.24
IBM Transformation Extender Advanced - addressed in versions 9.0.2.6, 10.0.1.7
IBM Watson Compare and Comply for IBM Cloud Pak for Data - update to 1.1.13
Liberty for Java for IBM Cloud - update to 3.62-20210922-1852
IBM Intelligent Operations Center - update to 5.2.3
IBM Copy Services Manager - update to 6.3.2
IBM Tivoli Netcool Impact - update to 7.1.0.24
IBM Transformation Extender Advanced - addressed in versions 9.0.2.6, 10.0.1.7
IBM Watson Compare and Comply for IBM Cloud Pak for Data - update to 1.1.13
Liberty for Java for IBM Cloud - update to 3.62-20210922-1852
External References
Related Security Bulletins
- Information disclosure in WebSphere Application Server
- Information disclosure in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM IoT MessageSight and WIoTP MessageGateway
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Information disclosure in IBM Tivoli Netcool Impact
- Information disclosure in IBM Copy Services Manager
- Information disclosure in IBM Transformation Extender Advanced
- Information disclosure in IBM Watson Compare and Comply for IBM Cloud Pak for Data
- Information disclosure in Liberty for Java for IBM Cloud
- Information disclosure in IBM Intelligent Operations Center
- Multiple vulnerabilities in IBM Cloud Transformation Advisor