LDAP injection in IBM WebSphere Application Server Liberty - CVE-2021-39031

 

LDAP injection in IBM WebSphere Application Server Liberty - CVE-2021-39031

Published: January 25, 2022


Vulnerability identifier: #VU59970
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-39031
CWE-ID: CWE-90
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to improper input validation when processing DLAP queries. A remote user can send a specially crafted request to modify the original LDAP query and gain unauthorized access to the application.


Affected software

IBM WebSphere Application Server Liberty
IBM Cloud Pak System
IBM Cloud Transformation Advisor
IBM SPSS Analytic Server
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Transformation Extender Advanced
IBM Cloud Application Business Insights
IBM MQ Operator
IBM Elastic Storage System
IBM Spectrum Scale for IBM Elastic Storage Server
IBM Common Licensing
IBM Cloud Private
IBM Copy Services Manager
IBM Supplied MQ Advanced Queue Manager Container images
IBM Cognos Controller

How to mitigate CVE-2021-39031

Install updates from vendor's website.

IBM WebSphere Application Server Liberty - update to 22.0.0.2
IBM Cloud Pak System - update to 2.3.3.6
IBM Cloud Private - addressed in versions 3.2.1.2203, 3.2.2.2203
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.7
IBM WIoTP MessageGateway - update to 5.0.0.2
IBM Transformation Extender Advanced - addressed in versions 9.0.2.6, 10.0.1.7
IBM Cloud Application Business Insights - addressed in versions 1.1.6.6, 1.1.7.3
IBM MQ Operator - addressed in versions 1.3.3, 1.8.0
IBM Elastic Storage System - addressed in versions 6.0.2.6, 6.1.2.3, 6.1.3.0
IBM Spectrum Scale for IBM Elastic Storage Server - addressed in versions 6.0.2.6, 6.1.2.3, 6.1.3.0
IBM Copy Services Manager - update to 6.3.2
IBM Common Licensing - update to 9.0.0.1
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.2.0.5-r1-eus, 9.2.5.0-r1
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2

External References

Related Security Bulletins