Improper input validation in Oracle Communications Cloud Native Core Policy - CVE-2021-23440

 

Improper input validation in Oracle Communications Cloud Native Core Policy - CVE-2021-23440

Published: January 27, 2022


Vulnerability identifier: #VU60087
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23440
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Policy (set-value) component in Oracle Communications Cloud Native Core Policy. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


Affected software

Oracle Communications Cloud Native Core Policy
IBM Watson Machine Learning Accelerator
QRadar Deployment Intelligence App
Db2 Big SQL
Red Hat Advanced Cluster Management for Kubernetes
IBM Fusion HCI
QRadar User Behavior Analytics
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2021-23440

Install updates from vendor's website.

Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
IBM Fusion HCI - update to 2.6.1
QRadar Deployment Intelligence App - update to 3.0.10
QRadar User Behavior Analytics - update to 4.1.13
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
Db2 Big SQL - update to 7.4.4

External References

Related Security Bulletins