Code Injection in dojo - CVE-2021-23450
Published: February 23, 2022
Vulnerability identifier: #VU60834
CSH Severity: High
CVSS v4 BT: 8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2021-23450
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The disclosed vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can inject and execute arbitrary script code via the setObject function.
Affected software
dojo
IBM TXSeries for Multiplatforms
IBM Cloud Application Business Insights
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Match 360
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Intelligent Operations Center
Oracle Communications WebRTC Session Controller
IBM Cloud Application Performance Management (APM)
IBM Cloud Pak for Business Automation
Financial Transaction Manager for ACH Services and Check Services
Financial Transaction Manager for Corporate Payment Services (CPS)
Financial Transaction Manager for Digital Payments (DP)
IBM Sterling B2B Integrator
IBM Tivoli Business Service Manager
IBM Tivoli Monitoring
IBM Business Process Manager
IBM Security Verify Governance
InfoSphere Master Data Management
IBM Business Automation Workflow
API Manager
IBM Integrated Analytics System
Oracle WebCenter Sites
API Gateway
Oracle WebLogic Server
IBM WebSphere Application Server Liberty
IBM Cloud Pak System
Oracle Communications Convergence
Tivoli Network Manager IP Edition
Administration Runtime Expert for i
Oracle Communications Policy Management
Financial Transaction Manager for High Value Payments
UrbanCode Build
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware
IBM DataPower Gateway
Primavera Unifier
IBM Enterprise Content Management System Monitor
IBM Copy Services Manager
IBM CICS TX Advanced
IBM CICS TX Standard
Oracle Commerce Merchandising
Oracle WebCenter Portal
Oracle Enterprise Manager Ops Center
Ubuntu
dojo (Ubuntu package)
IBM Qradar SIEM
IBM TXSeries for Multiplatforms
IBM Cloud Application Business Insights
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Match 360
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Intelligent Operations Center
Oracle Communications WebRTC Session Controller
IBM Cloud Application Performance Management (APM)
IBM Cloud Pak for Business Automation
Financial Transaction Manager for ACH Services and Check Services
Financial Transaction Manager for Corporate Payment Services (CPS)
Financial Transaction Manager for Digital Payments (DP)
IBM Sterling B2B Integrator
IBM Tivoli Business Service Manager
IBM Tivoli Monitoring
IBM Business Process Manager
IBM Security Verify Governance
InfoSphere Master Data Management
IBM Business Automation Workflow
API Manager
IBM Integrated Analytics System
Oracle WebCenter Sites
API Gateway
Oracle WebLogic Server
IBM WebSphere Application Server Liberty
IBM Cloud Pak System
Oracle Communications Convergence
Tivoli Network Manager IP Edition
Administration Runtime Expert for i
Oracle Communications Policy Management
Financial Transaction Manager for High Value Payments
UrbanCode Build
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware
IBM DataPower Gateway
Primavera Unifier
IBM Enterprise Content Management System Monitor
IBM Copy Services Manager
IBM CICS TX Advanced
IBM CICS TX Standard
Oracle Commerce Merchandising
Oracle WebCenter Portal
Oracle Enterprise Manager Ops Center
Ubuntu
dojo (Ubuntu package)
IBM Qradar SIEM
How to mitigate CVE-2021-23450
Install update from vendor's website.
dojo - addressed in versions 1.11.13, 1.12.11, 1.13.10, 1.14.9, 1.15.6, 1.16.5
API Manager - update to May 2023
API Gateway - update to May 2023
IBM Integrated Analytics System - update to 1.0.31.0
Netcool Operations Insight - update to 1.6.4
IBM Cloud Pak System - update to 2.3.3.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.7
IBM Match 360 - update to 4.0.8
IBM Security Guardium Key Lifecycle Manager (GKLM) - update to 4.1.1 FP6
Tivoli Network Manager IP Edition - update to 4.2.0.20
IBM WIoTP MessageGateway - update to 5.0.0.2
IBM Intelligent Operations Center - update to 5.2.3
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.14.0
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware - update to 8.1.14.0
IBM DataPower Gateway - addressed in versions 10.0.1.7, 10.0.4.0sr1, 10.5.0.0, 2018.4.1.20
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
dojo (Ubuntu package) - addressed in versions 1.10.4+dfsg-2ubuntu0.1~esm1, 1.15.0+dfsg1-1ubuntu0.1~esm1, 1.15.4+dfsg1-1ubuntu0.1
Financial Transaction Manager for ACH Services and Check Services - update to 3.0.5.4 iFix 28
Financial Transaction Manager for High Value Payments - update to 3.2.11
Financial Transaction Manager for Corporate Payment Services (CPS) - update to 3.2.11
Financial Transaction Manager for Digital Payments (DP) - update to 3.2.11
IBM Enterprise Content Management System Monitor - update to 5.5.9
IBM Sterling B2B Integrator - update to 6.1.2.2
UrbanCode Build - update to 6.1.7.10
IBM Tivoli Business Service Manager - update to 6.2.0.5
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Copy Services Manager - update to 6.3.2
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
IBM Business Process Manager - addressed in versions 8.5.7.CF201706, 8.6.0.CF201803
IBM Security Verify Governance - update to 10.0.1.0.5
InfoSphere Master Data Management - addressed in versions 11.6.0.12 IF003, 12.0.0.0 IF006, 14.0.0.0 IF001
IBM Business Automation Workflow - addressed in versions 21.0.3, 21.0.3-IF011, 22.0.1, 22.0.1-IF001
API Manager - update to May 2023
API Gateway - update to May 2023
IBM Integrated Analytics System - update to 1.0.31.0
Netcool Operations Insight - update to 1.6.4
IBM Cloud Pak System - update to 2.3.3.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.7
IBM Match 360 - update to 4.0.8
IBM Security Guardium Key Lifecycle Manager (GKLM) - update to 4.1.1 FP6
Tivoli Network Manager IP Edition - update to 4.2.0.20
IBM WIoTP MessageGateway - update to 5.0.0.2
IBM Intelligent Operations Center - update to 5.2.3
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.14.0
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware - update to 8.1.14.0
IBM DataPower Gateway - addressed in versions 10.0.1.7, 10.0.4.0sr1, 10.5.0.0, 2018.4.1.20
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
dojo (Ubuntu package) - addressed in versions 1.10.4+dfsg-2ubuntu0.1~esm1, 1.15.0+dfsg1-1ubuntu0.1~esm1, 1.15.4+dfsg1-1ubuntu0.1
Financial Transaction Manager for ACH Services and Check Services - update to 3.0.5.4 iFix 28
Financial Transaction Manager for High Value Payments - update to 3.2.11
Financial Transaction Manager for Corporate Payment Services (CPS) - update to 3.2.11
Financial Transaction Manager for Digital Payments (DP) - update to 3.2.11
IBM Enterprise Content Management System Monitor - update to 5.5.9
IBM Sterling B2B Integrator - update to 6.1.2.2
UrbanCode Build - update to 6.1.7.10
IBM Tivoli Business Service Manager - update to 6.2.0.5
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Copy Services Manager - update to 6.3.2
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
IBM Business Process Manager - addressed in versions 8.5.7.CF201706, 8.6.0.CF201803
IBM Security Verify Governance - update to 10.0.1.0.5
InfoSphere Master Data Management - addressed in versions 11.6.0.12 IF003, 12.0.0.0 IF006, 14.0.0.0 IF001
IBM Business Automation Workflow - addressed in versions 21.0.3, 21.0.3-IF011, 22.0.1, 22.0.1-IF001
External References
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2313033
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBDOJO-2313034
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2313035
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-2313036
- https://snyk.io/vuln/SNYK-JS-DOJO-1535223
- https://github.com/dojo/dojo/commit/b7b8b279f3e082e9d4b54144fe831bdc77b2e0c9
Related Security Bulletins
- Prototype pollution in Dojo
- IBM WebSphere Application Server update for Dojo
- IBM Cloud Application Business Insights update for dojo
- IBM Spectrum Protect for Virtual Environments update for Dojo
- Code injection in IBM Cloud APM
- Multiple vulnerabilities in Primavera Unifier
- Multiple vulnerabilities in Oracle Communications Policy Management
- Code Injection in IBM DataPower Gateway
- Code Injection in IBM CICS TX Standard
- Code Injection in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Code Injection in IBM Match 360
- Multiple vulnerabilities in IBM WIoTP MessageGateway/IoT MessageSight
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Cloud Pak System third-party components
- Multiple vulnerabilities in IBM Security Guardium Key Lifecycle Manager
- Code Injection in IBM Intelligent Operations Center
- Code Injection in IBM Intelligent Operations Center
- Code Injection in IBM Business Automation Workflow and IBM Business Process Manager (BPM)
- Multiple vulnerabilities in Oracle Communications WebRTC Session Controller
- Code Injection in Oracle Communications Convergence
- Code Injection in Oracle Enterprise Manager Ops Center
- Code Injection in IBM Enterprise Content Management System Monitor
- Multiple vulnerabilities in Oracle WebCenter Sites
- Multiple vulnerabilities in Oracle WebCenter Portal
- Code Injection in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Code Injection in IBM Tivoli Business Service Manager
- Multiple vulnerabilities in Axway API Gateway and API Manager
- Code Injection in IBM Financial Transaction Manager for Digital Payments, High Value Payments and Corporate Payment Services
- Multiple vulnerabilities in IBM Copy Services Manager
- Code injection in IBM Security Verify Governance
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM UrbanCode Build
- Code injection in IBM Administration Runtime Expert for i
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition (ITNM)
- IBM InfoSphere Master Data Management update for Dojo
- IBM TXSeries for Multiplatforms update for Dojo
- Code Injection in Oracle Commerce Merchandising
- Ubuntu update for dojo
- IBM Integrated Analytics System update for dojo
- Multiple vulnerabilities in IBM Financial Transaction Manager for ACH Services and Check Services for Multi-Platform