XML External Entity injection in jdom - CVE-2021-33813

 

XML External Entity injection in jdom - CVE-2021-33813

Published: March 29, 2022


Vulnerability identifier: #VU61721
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33813
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied XML input within the SAXBuilder. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.


Affected software

jdom
Amazon Linux AMI
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Development Tools
openEuler
Fedora
IBM Integration Bus
Jazz for Service Management
Log Analysis
Jira Service Management Server
Jira Service Management Data Center
IBM Sterling B2B Integrator
IBM Maximo Asset Management
Red Hat Decision Manager
Jira Software Data Center
Netcool Operations Insight
IBM Sterling Secure Proxy
Tivoli Composite Application Manager for Transactions
IBM Common Licensing
IBM Security Verify Governance
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
IBM Content Navigator
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Oracle Business Intelligence Enterprise Edition
IBM Business Automation Manager Open Editions
Storage Resource Manager
Engineering Test Management
IBM Engineering Lifecycle Optimization - Publishing
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Oracle Communications Instant Messaging Server
Oracle Healthcare Foundation
Oracle WebCenter Portal
Siebel CRM Deployment
Siebel CRM Integration
Jira Software Server
Oracle Service Bus
jaxen
jdom
jdom2
jdom2-help
Dell EMC Storage Monitoring and Reporting (SMR)
Jazz Foundation
IBM App Connect Enterprise
Dell EMC VxRail Appliance
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware
IBM Spectrum Protect Backup-Archive Client
IBM Spectrum Protect for Space Management

How to mitigate CVE-2021-33813

Install updates from vendor's website.

jdom - update to 2.0.6.1
Jazz for Service Management - update to 1.1.3.25
Log Analysis - update to 1.3.8
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008, 3.2.0 IF004
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.1.3
Jira Service Management Server - update to 5.12.22
Jira Service Management Data Center - update to 5.12.22
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.0.8, 6.1.1.4, 6.1.2.3, 6.2.0.0
Red Hat Decision Manager - update to 7.12.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.12.1
IBM Business Automation Manager Open Editions - update to 8.0.7
Jira Software Server - update to 9.12.22
Jira Software Data Center - update to 9.12.22
jaxen - update to 1.1.1-150000.5.3.1
jdom - update to 1.1.3-27.fc35
jdom - update to 1.1.3-30
jdom - update to 1.1-150000.5.3.1
Netcool Operations Insight - update to 1.6.8
jdom2 - update to 2.0.6-3.3.1
jdom2 - update to 2.0.6-15
jdom2-help - update to 2.0.6-15
jdom2 - update to 2.0.6-24.fc35
Storage Resource Manager - update to 5.0.2.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.2.2
IBM Sterling Secure Proxy - update to 6.0.3 iFix 08
Engineering Test Management - addressed in versions 7.0.1.0.21, 7.0.2.0.22
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.1.23, 7.0.2.25
Jazz Foundation - addressed in versions 7.0.2.0.31, 7.0.3.0.8
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
Dell EMC VxRail Appliance - update to 8.0.213
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.17.2
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware - update to 8.1.17.2
IBM Spectrum Protect Backup-Archive Client - update to 8.1.17.2
IBM Spectrum Protect for Space Management - update to 8.1.17.2
IBM Common Licensing - update to 9.0.0.6
IBM Security Verify Governance - update to 10.0.2.0.3
IBM App Connect Enterprise - addressed in versions 11.0.0.21, 11.0.0.22, 12.0.9.0
IBM Business Automation Workflow - addressed in versions 21.0.3 IF024, 23.0.1 IF002
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.24, 23.0.1.2
IBM Automation Decision Services - update to 23.0.2.0.4

External References

Related Security Bulletins