Information disclosure in IBM WebSphere Application Server - CVE-2021-29842

 

Information disclosure in IBM WebSphere Application Server - CVE-2021-29842

Published: September 16, 2021


Vulnerability identifier: #VU56660
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29842
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output, when the WebSphere Application Server is configured with a federated repository. A remote attacker can gain unauthorized access to sensitive information on the system.



Affected software

IBM WebSphere Application Server
IBM IoT MessageSight
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM WIoTP MessageGateway
IBM Intelligent Operations Center
IBM Tivoli Monitoring
IBM Tivoli Netcool Impact
IBM Transformation Extender Advanced
IBM Copy Services Manager
IBM Watson Compare and Comply for IBM Cloud Pak for Data
Liberty for Java for IBM Cloud

How to mitigate CVE-2021-29842

Install updates from vendor's website.

IBM WebSphere Application Server - addressed in versions 7.0.0.45 PH38929, 8.0.0.15 PH38929, 8.5.5.20 PH38929, 9.0.5.9 PH38929
IBM Intelligent Operations Center - update to 5.2.3
IBM Copy Services Manager - update to 6.3.2
IBM Tivoli Netcool Impact - update to 7.1.0.24
IBM Transformation Extender Advanced - addressed in versions 9.0.2.6, 10.0.1.7
IBM Watson Compare and Comply for IBM Cloud Pak for Data - update to 1.1.13
Liberty for Java for IBM Cloud - update to 3.62-20210922-1852

External References

Related Security Bulletins