Code Injection in Logback - CVE-2021-42550
Published: December 19, 2021
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote user can send a specially crafted request to the application and execute arbitrary code on the target system by tricking the application to load a malicious configuration from a remote LDAP server.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Decision Manager
IBM Maximo Asset Management
IBM Maximo Application Suite
EMC NetWorker Server
API Manager
Cloudera Data Platform Private Cloud Base for IBM
API Gateway
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Server Module
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
SINEC NMS
Zabbix
IBM Cloud Pak System
Planning Analytics Cartridge for Cloud Pak for Data
IBM Planning Analytics Workspace
Dell EMC Cloud Disaster Recovery
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Contrail Networking
sbt-bootstrap
sbt
logback (Ubuntu package)
logback-examples
logback-help
logback-access
logback
minlog
minlog-javadoc
antlr3-java-javadoc
antlr3-javadoc
antlr3-tool
antlr3-java
antlr3-bootstrap-tool
maven-lib
maven
maven-javadoc
xmvn-minimal
xmvn
xmvn-install
xmvn-core
xmvn-tools-javadoc
xmvn-resolve
xmvn-parent
xmvn-subst
xmvn-api
xmvn-connector
xmvn-connector-javadoc
xmvn-mojo-javadoc
xmvn-mojo
Cloud Pak for Security (CP4S)
watsonx.data
IBM Spectrum Scale
Operational Decision Manager
How to mitigate CVE-2021-42550
API Manager - update to February 2022
API Gateway - update to February 2022
SINEC NMS - update to 1.0.3
IBM Cloud Pak System - update to 2.3.3.6
Zabbix - addressed in versions 4.0.37 rc1, 5.0.19 rc2, 5.4.9 rc2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.8
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.12.1
Red Hat Decision Manager - update to 7.12.1
sbt-bootstrap - update to 0.13.18-150200.4.7.8
sbt - update to 0.13.18-150200.4.7.8
logback (Ubuntu package) - addressed in versions 1:1.1.3-2ubuntu0.1~esm1, 1:1.2.3-2ubuntu1~18.04.1+esm1, 1:1.2.3-5ubuntu0.1~esm1, 1:1.2.10-1ubuntu0.1~esm1
logback-examples - addressed in versions 1.2.8-1, 1.2.8-2
logback-help - addressed in versions 1.2.8-1, 1.2.8-2
logback-access - addressed in versions 1.2.8-1, 1.2.8-2
logback - addressed in versions 1.2.8-1, 1.2.8-2
minlog - update to 1.3.1-150200.3.7.8
minlog-javadoc - update to 1.3.1-150200.3.7.8
Cloud Pak for Security (CP4S) - update to 1.10.14.0
watsonx.data - update to 2.0.3
IBM Planning Analytics Workspace - update to 2.0.84
antlr3-java-javadoc - update to 3.5.3-150200.3.11.8
antlr3-javadoc - update to 3.5.3-150200.3.11.8
antlr3-tool - update to 3.5.3-150200.3.11.8
antlr3-java - update to 3.5.3-150200.3.11.8
antlr3-bootstrap-tool - update to 3.5.3-150200.3.11.8
maven-lib - update to 3.8.6-150200.4.9.8
maven - update to 3.8.6-150200.4.9.8
maven-javadoc - update to 3.8.6-150200.4.9.8
xmvn-minimal - update to 4.0.0-150200.3.7.1
xmvn - update to 4.0.0-150200.3.7.1
xmvn-install - update to 4.0.0-150200.3.7.1
xmvn-core - update to 4.0.0-150200.3.7.1
xmvn-tools-javadoc - update to 4.0.0-150200.3.7.1
xmvn-resolve - update to 4.0.0-150200.3.7.1
xmvn-parent - update to 4.0.0-150200.3.7.1
xmvn-subst - update to 4.0.0-150200.3.7.1
xmvn-api - update to 4.0.0-150200.3.7.1
xmvn-connector - update to 4.0.0-150200.3.7.3
xmvn-connector-javadoc - update to 4.0.0-150200.3.7.3
xmvn-mojo-javadoc - update to 4.0.0-150200.3.7.8
xmvn-mojo - update to 4.0.0-150200.3.7.8
IBM Spectrum Scale - update to 5.1.6.1
IBM Maximo Asset Management - update to 7.6.1.3.16
IBM Maximo Application Suite - update to 8.6.8
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
EMC NetWorker Server - update to 19.7.0.0
Dell EMC Cloud Disaster Recovery - update to 19.12
Contrail Networking - update to 2011.L5
External References
Related Security Bulletins
- Remote code execution in logback
- Remote code execution in Zabbix Java Gateway (Apache Log4j component)
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in Red Hat Decision Manager
- Multiple vulnerabilities in Juniper Networks Contrail Networking
- Siemens SINEC update for logback
- Multiple vulnerabilities in Dell EMC NetWorker
- Remote code execution in Dell Cloud Disaster Recovery
- Code Injection in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in API Gateway and API Manager
- Multiple vulnerabilities in IBM Cloud Pak System
- SUSE update for maven and recommended update for antlr3, minlog, sbt, xmvn
- Multiple vulnerabilities in IBM Spectrum Scale Transparent Cloud Tiering
- Multiple vulnerabilities in IBM Planning Analytics Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Code Injection in IBM Maximo Manage application in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Maximo Asset Management
- openEuler update for logback
- openEuler 20.03 LTS SP3 update for logback
- Multiple vulnerabilities in IBM Operational Decision Manager
- IBM watsonx.data update for Logback, Guava and Apache HTTPClient
- Ubuntu update for logback
- Multiple vulnerabilities in Cloudera Data Platform Private Cloud Base with IBM (CDP)