Spoofing attack in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - CVE-2021-39038
Published: February 25, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform clickjacking attack.
The vulnerability exists due to incorrect processing of user-supplied data, when REST API discovery is configured through the WebSphere administrative console Web Container settings to enable the API Discovery service, or through IBM WebSphere Application Server Liberty features mpOpenAPI-1.0, mpOpenAPI-1.1, mpOpenAPI-2.0, apiDiscovery-1.0, openapi-3.0 or openapi-3.1. A remote attacker can perform clickjacking attack.
Affected software
IBM WebSphere Application Server Liberty
IBM MQ Operator
IBM Cloud Transformation Advisor
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Intelligent Operations Center
IBM Tivoli Netcool Impact
IBM Cloud Pak for Multicloud Management Monitoring
IBM Spectrum Scale for IBM Elastic Storage Server
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Watson Explorer Foundational Components
IBM Watson Explorer Analytical Components
IBM Watson Explorer Deep Analytics Edition oneWEX
IBM Watson Explorer Deep Analytics Edition Analytical Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
IBM Copy Services Manager
Voice Gateway
IBM Cognos Controller
IBM InfoSphere Information Server
How to mitigate CVE-2021-39038
IBM Cloud Transformation Advisor - update to 3.1.0
IBM WIoTP MessageGateway - update to 5.0.0.2
IBM Intelligent Operations Center - update to 5.2.3
IBM Tivoli Netcool Impact - update to 7.1.0.26
IBM Watson Explorer Foundational Components - update to 11.0.2.14
IBM Watson Explorer Analytical Components - update to 11.0.2.14
IBM Watson Explorer Deep Analytics Edition oneWEX - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.10
Voice Gateway - addressed in versions 1.0.7.4, 1.0.7.12
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
IBM Spectrum Scale for IBM Elastic Storage Server - addressed in versions 6.0.2.6, 6.1.2.3, 6.1.3.0
IBM Copy Services Manager - update to 6.3.2
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
IBM CICS TX Standard - update to 11.1.0.0 ifix2
IBM InfoSphere Information Server - addressed in versions 11.7.1.0, 11.7.1.4
External References
Related Security Bulletins
- Clickjacking attack in IBM WebSphere Application Server
- Multiple vulnerabilities in IBM WIoTP MessageGateway/IoT MessageSight
- Clickjacking attack in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM Watson Explorer
- Clickjacking attack in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in IBM MQ Operator
- Clickjacking attack in IBM Intelligent Operations Center
- Clickjacking attack in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Copy Services Manager
- Multiple vulnerabilities in IBM Cognos Controller
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM Spectrum Scale for IBM Elastic Storage Server
- Spoofing attack in IBM Voice Gateway