Improper input validation in Netty - CVE-2021-37137

 

Improper input validation in Netty - CVE-2021-37137

Published: January 23, 2022 / Updated: May 5, 2026


Vulnerability identifier: #VU59924
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2021-37137
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Snappy frame decoder function. A remote attacker can send specially crafted HTTP requests and perform a denial of service attack.


Affected software

Netty
Debian Linux
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
Ubuntu
openEuler
IBM Observability with Instana
Log Analysis
IBM Operations Analytics Predictive Insights
Netcool Operations Insight
Oracle Communications Cloud Native Core Binding Support Function
IBM Cloud Transformation Advisor
OpenShift Logging
Red Hat Satellite
Oracle Communications Diameter Signaling Router
Oracle Banking APIs
Autodesk Infraworks
Red Hat Integration - Service Registry
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling B2B Integrator
HPE Telco IP Mediation E-Media
IBM Watson Machine Learning Accelerator
Security QRadar EDR
DataStage on Cloud Pak for Data
Oracle Banking Digital Experience
IBM Cloud Pak for Watson AIOps
IBM Sterling Order Management
Communications Unified Assurance
Voice Gateway
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
JBoss Enterprise Application Platform
AMQ Streams
AMQ Broker
Fuse
PeopleSoft Enterprise PeopleTools
Oracle Commerce Guided Search
Oracle Communications BRM - Elastic Charging Engine
Oracle WebCenter Portal
libnetty-java (Ubuntu package)
netty-help
netty
netty (Debian package)
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
JBoss Data Grid
watsonx.data
IBM Security Guardium

How to mitigate CVE-2021-37137

Install updates from vendor's website.

Netty - update to 4.1.68
Log Analysis - update to 1.3.8
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
Netcool Operations Insight - update to 1.6.5
IBM Cloud Transformation Advisor - update to 3.2.1
Security QRadar EDR - update to 3.12.15
DataStage on Cloud Pak for Data - update to 4.8.5
OpenShift Logging - addressed in versions 5.2.10, 5.3.7, 5.4.1
Communications Unified Assurance - update to 6.0.4
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.0
JBoss Enterprise Application Platform - update to 7.4.5
Oracle Communications BRM - Elastic Charging Engine - update to 12.0.0.5.1
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
libnetty-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.1.48-4+deb11u1build0.22.04.1, 1:4.1.48-5ubuntu0.1
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
Cloud Pak for Security (CP4S) - update to 1.10.12.0
AMQ Streams - addressed in versions 2.0.0, 2.4.0, 2.5.0
watsonx.data - update to 2.0.2
Red Hat Integration - Service Registry - update to 2.3.0
IBM Cloud Pak for Watson AIOps - update to 3.7.1
netty-help - update to 4.1.13-12
netty - update to 4.1.13-12
netty - addressed in versions 4.1.44.Final-150200.3.4.2, 4.1.44.Final-150300.4.3.2, 4.1.44.Final-150400.3.3.2
netty (Debian package) - update to 1:4.1.48-4+deb11u1
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.8.0
IBM Sterling B2B Integrator - update to 6.1.2.1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
AMQ Broker - update to 7.9.1
Fuse - update to 7.10.0
JBoss Data Grid - update to 8.3.0
HPE Telco IP Mediation E-Media - update to 8.5.1
IBM Sterling Order Management - update to 10.0.0.29
IBM Security Guardium - addressed in versions 11.0p360, 11.0p430

External References

Related Security Bulletins