Spoofing attack in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - CVE-2021-39038

 

Spoofing attack in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - CVE-2021-39038

Published: February 25, 2022


Vulnerability identifier: #VU60870
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-39038
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform clickjacking attack.

The vulnerability exists due to incorrect processing of user-supplied data, when REST API discovery is configured through the WebSphere administrative console Web Container settings to enable the API Discovery service, or through IBM WebSphere Application Server Liberty features mpOpenAPI-1.0, mpOpenAPI-1.1, mpOpenAPI-2.0, apiDiscovery-1.0, openapi-3.0 or openapi-3.1. A remote attacker can perform clickjacking attack.


Affected software

IBM WebSphere Application Server
IBM WebSphere Application Server Liberty
IBM MQ Operator
IBM Cloud Transformation Advisor
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Intelligent Operations Center
IBM Tivoli Netcool Impact
IBM Cloud Pak for Multicloud Management Monitoring
IBM Spectrum Scale for IBM Elastic Storage Server
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Watson Explorer Foundational Components
IBM Watson Explorer Analytical Components
IBM Watson Explorer Deep Analytics Edition oneWEX
IBM Watson Explorer Deep Analytics Edition Analytical Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
IBM Copy Services Manager
Voice Gateway
IBM Cognos Controller
IBM InfoSphere Information Server

How to mitigate CVE-2021-39038

Install updates from vendor's website.

IBM MQ Operator - addressed in versions 1.3.5, 2.0.0
IBM Cloud Transformation Advisor - update to 3.1.0
IBM WIoTP MessageGateway - update to 5.0.0.2
IBM Intelligent Operations Center - update to 5.2.3
IBM Tivoli Netcool Impact - update to 7.1.0.26
IBM Watson Explorer Foundational Components - update to 11.0.2.14
IBM Watson Explorer Analytical Components - update to 11.0.2.14
IBM Watson Explorer Deep Analytics Edition oneWEX - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.10
Voice Gateway - addressed in versions 1.0.7.4, 1.0.7.12
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
IBM Spectrum Scale for IBM Elastic Storage Server - addressed in versions 6.0.2.6, 6.1.2.3, 6.1.3.0
IBM Copy Services Manager - update to 6.3.2
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
IBM CICS TX Standard - update to 11.1.0.0 ifix2
IBM InfoSphere Information Server - addressed in versions 11.7.1.0, 11.7.1.4

External References

Related Security Bulletins