Buffer overflow in Apache Mina SSHD - CVE-2021-30129
Published: September 29, 2021
Vulnerability identifier: #VU56931
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30129
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the sshd-core of Apache Mina SSHD. A remote attacker can send specially crafted requests to the server, trigger buffer overflow and perform a denial of service (DoS) attack.
Affected software
Apache Mina SSHD
Oracle Communications Cloud Native Core Console
OSS Support Tools
JD Edwards EnterpriseOne Tools
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
JBoss Enterprise Application Platform
Wildfly Core
Fuse
IBM Business Automation Manager Open Editions
Oracle FLEXCUBE Universal Banking
Middleware Common Libraries and Tools
Oracle Banking Trade Finance
Oracle Banking Treasury Management
IBM Sterling Partner Engagement Manager
Oracle Global Lifecycle Management NextGen OUI Framework
Oracle Banking Payments
Oracle Retail Customer Management and Segmentation Foundation
openEuler
apache-sshd
apache-sshd-javadoc
Oracle Communications Cloud Native Core Console
OSS Support Tools
JD Edwards EnterpriseOne Tools
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
JBoss Enterprise Application Platform
Wildfly Core
Fuse
IBM Business Automation Manager Open Editions
Oracle FLEXCUBE Universal Banking
Middleware Common Libraries and Tools
Oracle Banking Trade Finance
Oracle Banking Treasury Management
IBM Sterling Partner Engagement Manager
Oracle Global Lifecycle Management NextGen OUI Framework
Oracle Banking Payments
Oracle Retail Customer Management and Segmentation Foundation
openEuler
apache-sshd
apache-sshd-javadoc
How to mitigate CVE-2021-30129
Install updates from vendor's website.
Apache Mina SSHD - update to 2.7.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.4
JBoss Enterprise Application Platform - update to 7.4.2
IBM Business Automation Manager Open Editions - update to 8.0.3
Wildfly Core - update to 17.0.0
JD Edwards EnterpriseOne Tools - update to 9.2.7.3
Oracle Global Lifecycle Management NextGen OUI Framework - update to 13.9.4.2.10
Oracle FLEXCUBE Universal Banking - update to 14.3.0
apache-sshd - update to 2.2.0-2
apache-sshd-javadoc - update to 2.2.0-2
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
Fuse - update to 7.10.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.4
JBoss Enterprise Application Platform - update to 7.4.2
IBM Business Automation Manager Open Editions - update to 8.0.3
Wildfly Core - update to 17.0.0
JD Edwards EnterpriseOne Tools - update to 9.2.7.3
Oracle Global Lifecycle Management NextGen OUI Framework - update to 13.9.4.2.10
Oracle FLEXCUBE Universal Banking - update to 14.3.0
apache-sshd - update to 2.2.0-2
apache-sshd-javadoc - update to 2.2.0-2
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
Fuse - update to 7.10.0
External References
- https://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f%40%3Cusers.mina.apache.org%3E
- https://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f@%3Cusers.mina.apache.org%3E
- https://lists.apache.org/thread.html/red01829efa2a8c893c4baff4f23c9312bd938543a9b8658e172b853b@%3Cannounce.apache.org%3E
- http://www.openwall.com/lists/oss-security/2021/07/12/1
- https://github.com/advisories/GHSA-9279-7hph-r3xw
Related Security Bulletins
- Denial of service in Apache Mina SSHD
- WildFly Core update for Apache Mina SSHD
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Console
- Multiple vulnerabilities in Oracle FLEXCUBE Universal Banking
- Multiple vulnerabilities in Oracle Banking Treasury Management
- Multiple vulnerabilities in Oracle Banking Trade Finance
- Multiple vulnerabilities in Oracle Banking Payments
- Buffer overflow in Middleware Common Libraries and Tools
- Multiple vulnerabilities in OSS Support Tools
- Multiple vulnerabilities in Oracle Retail Customer Management and Segmentation Foundation
- Multiple vulnerabilities in Oracle Global Lifecycle Management NextGen OUI Framework
- Buffer overflow in IBM Sterling Partner Engagement Manager
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Red Hat Process Automation Manager
- openEuler update for apache-sshd
- Multiple vulnerabilities in Fuse 7.10