Code Injection in dojo - CVE-2021-23450

 

Code Injection in dojo - CVE-2021-23450

Published: February 23, 2022


Vulnerability identifier: #VU60834
CSH Severity: High
CVSS v4 BT: 8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2021-23450
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can inject and execute arbitrary script code via the setObject function.


Affected software

dojo
IBM TXSeries for Multiplatforms
IBM Cloud Application Business Insights
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Match 360
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Intelligent Operations Center
Oracle Communications WebRTC Session Controller
IBM Cloud Application Performance Management (APM)
IBM Cloud Pak for Business Automation
Financial Transaction Manager for ACH Services and Check Services
Financial Transaction Manager for Corporate Payment Services (CPS)
Financial Transaction Manager for Digital Payments (DP)
IBM Sterling B2B Integrator
IBM Tivoli Business Service Manager
IBM Tivoli Monitoring
IBM Business Process Manager
IBM Security Verify Governance
InfoSphere Master Data Management
IBM Business Automation Workflow
API Manager
IBM Integrated Analytics System
Oracle WebCenter Sites
API Gateway
Oracle WebLogic Server
IBM WebSphere Application Server Liberty
IBM Cloud Pak System
Oracle Communications Convergence
Tivoli Network Manager IP Edition
Administration Runtime Expert for i
Oracle Communications Policy Management
Financial Transaction Manager for High Value Payments
UrbanCode Build
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware
IBM DataPower Gateway
Primavera Unifier
IBM Enterprise Content Management System Monitor
IBM Copy Services Manager
IBM CICS TX Advanced
IBM CICS TX Standard
Oracle Commerce Merchandising
Oracle WebCenter Portal
Oracle Enterprise Manager Ops Center
Ubuntu
dojo (Ubuntu package)
IBM Qradar SIEM

How to mitigate CVE-2021-23450

Install update from vendor's website.

dojo - addressed in versions 1.11.13, 1.12.11, 1.13.10, 1.14.9, 1.15.6, 1.16.5
API Manager - update to May 2023
API Gateway - update to May 2023
IBM Integrated Analytics System - update to 1.0.31.0
Netcool Operations Insight - update to 1.6.4
IBM Cloud Pak System - update to 2.3.3.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.7
IBM Match 360 - update to 4.0.8
IBM Security Guardium Key Lifecycle Manager (GKLM) - update to 4.1.1 FP6
Tivoli Network Manager IP Edition - update to 4.2.0.20
IBM WIoTP MessageGateway - update to 5.0.0.2
IBM Intelligent Operations Center - update to 5.2.3
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.14.0
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware - update to 8.1.14.0
IBM DataPower Gateway - addressed in versions 10.0.1.7, 10.0.4.0sr1, 10.5.0.0, 2018.4.1.20
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
dojo (Ubuntu package) - addressed in versions 1.10.4+dfsg-2ubuntu0.1~esm1, 1.15.0+dfsg1-1ubuntu0.1~esm1, 1.15.4+dfsg1-1ubuntu0.1
Financial Transaction Manager for ACH Services and Check Services - update to 3.0.5.4 iFix 28
Financial Transaction Manager for High Value Payments - update to 3.2.11
Financial Transaction Manager for Corporate Payment Services (CPS) - update to 3.2.11
Financial Transaction Manager for Digital Payments (DP) - update to 3.2.11
IBM Enterprise Content Management System Monitor - update to 5.5.9
IBM Sterling B2B Integrator - update to 6.1.2.2
UrbanCode Build - update to 6.1.7.10
IBM Tivoli Business Service Manager - update to 6.2.0.5
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Copy Services Manager - update to 6.3.2
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
IBM Business Process Manager - addressed in versions 8.5.7.CF201706, 8.6.0.CF201803
IBM Security Verify Governance - update to 10.0.1.0.5
InfoSphere Master Data Management - addressed in versions 11.6.0.12 IF003, 12.0.0.0 IF006, 14.0.0.0 IF001
IBM Business Automation Workflow - addressed in versions 21.0.3, 21.0.3-IF011, 22.0.1, 22.0.1-IF001

External References

Related Security Bulletins