XML External Entity injection in jdom - CVE-2021-33813
Published: March 29, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input within the SAXBuilder. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
Affected software
Amazon Linux AMI
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Development Tools
openEuler
Fedora
IBM Integration Bus
Jazz for Service Management
Log Analysis
Jira Service Management Server
Jira Service Management Data Center
IBM Sterling B2B Integrator
IBM Maximo Asset Management
Red Hat Decision Manager
Jira Software Data Center
Netcool Operations Insight
IBM Sterling Secure Proxy
Tivoli Composite Application Manager for Transactions
IBM Common Licensing
IBM Security Verify Governance
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
IBM Content Navigator
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Oracle Business Intelligence Enterprise Edition
IBM Business Automation Manager Open Editions
Storage Resource Manager
Engineering Test Management
IBM Engineering Lifecycle Optimization - Publishing
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Oracle Communications Instant Messaging Server
Oracle Healthcare Foundation
Oracle WebCenter Portal
Siebel CRM Deployment
Siebel CRM Integration
Jira Software Server
Oracle Service Bus
jaxen
jdom
jdom2
jdom2-help
Dell EMC Storage Monitoring and Reporting (SMR)
Jazz Foundation
IBM App Connect Enterprise
Dell EMC VxRail Appliance
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware
IBM Spectrum Protect Backup-Archive Client
IBM Spectrum Protect for Space Management
How to mitigate CVE-2021-33813
Jazz for Service Management - update to 1.1.3.25
Log Analysis - update to 1.3.8
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008, 3.2.0 IF004
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.1.3
Jira Service Management Server - update to 5.12.22
Jira Service Management Data Center - update to 5.12.22
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.0.8, 6.1.1.4, 6.1.2.3, 6.2.0.0
Red Hat Decision Manager - update to 7.12.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.12.1
IBM Business Automation Manager Open Editions - update to 8.0.7
Jira Software Server - update to 9.12.22
Jira Software Data Center - update to 9.12.22
jaxen - update to 1.1.1-150000.5.3.1
jdom - update to 1.1.3-27.fc35
jdom - update to 1.1.3-30
jdom - update to 1.1-150000.5.3.1
Netcool Operations Insight - update to 1.6.8
jdom2 - update to 2.0.6-3.3.1
jdom2 - update to 2.0.6-15
jdom2-help - update to 2.0.6-15
jdom2 - update to 2.0.6-24.fc35
Storage Resource Manager - update to 5.0.2.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.2.2
IBM Sterling Secure Proxy - update to 6.0.3 iFix 08
Engineering Test Management - addressed in versions 7.0.1.0.21, 7.0.2.0.22
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.1.23, 7.0.2.25
Jazz Foundation - addressed in versions 7.0.2.0.31, 7.0.3.0.8
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
Dell EMC VxRail Appliance - update to 8.0.213
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.17.2
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware - update to 8.1.17.2
IBM Spectrum Protect Backup-Archive Client - update to 8.1.17.2
IBM Spectrum Protect for Space Management - update to 8.1.17.2
IBM Common Licensing - update to 9.0.0.6
IBM Security Verify Governance - update to 10.0.2.0.3
IBM App Connect Enterprise - addressed in versions 11.0.0.21, 11.0.0.22, 12.0.9.0
IBM Business Automation Workflow - addressed in versions 21.0.3 IF024, 23.0.1 IF002
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.24, 23.0.1.2
IBM Automation Decision Services - update to 23.0.2.0.4
External References
- https://github.com/hunterhacker/jdom/pull/188
- https://github.com/hunterhacker/jdom/releases
- https://alephsecurity.com/vulns/aleph-2021003
- https://lists.debian.org/debian-lts-announce/2021/06/msg00026.html
- https://lists.apache.org/thread.html/rbc075a4ac85e7a8e47420b7383f16ffa0af3b792b8423584735f369f@%3Cissues.solr.apache.org%3E
- https://lists.apache.org/thread.html/r9974f64723875052e02787b2a5eda689ac5247c71b827d455e5dc9a6@%3Cissues.solr.apache.org%3E
- https://lists.apache.org/thread.html/r89b3800cfabb1e773e49425e5d4239c28a659839a2eca6af3431482e@%3Cissues.solr.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/07/msg00012.html
- https://lists.apache.org/thread.html/rfb7a93e40ebeb1e0068cde0bf3834dcab46bb1ef06d6424db48ed9fd@%3Cdev.tika.apache.org%3E
- https://lists.apache.org/thread.html/r5674106135bb1a6ef57483f4c63a9c44bca85d0e2a8a05895a8f1d89@%3Cissues.solr.apache.org%3E
- https://lists.apache.org/thread.html/r845e987b7cd8efe610284958e997b84583f5a98d3394adc09e3482fe@%3Cissues.solr.apache.org%3E
- https://lists.apache.org/thread.html/r6db397ae7281ead825338200d1f62d2827585a70797cc9ac0c4bd23f@%3Cissues.solr.apache.org%3E
- https://lists.apache.org/thread.html/r21c406c7ed88fe340db7dbae75e58355159e6c324037c7d5547bf40b@%3Cissues.solr.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EWFVYTHGILOQXUA7U3SPOERQXL7OPSZG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AH46QHE5GIMT6BL6C3GDTOYF27JYILXM/
Related Security Bulletins
- XXE in JDOM
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in Red Hat Decision Manager
- Multiple vulnerabilities in Oracle Communications Messaging Server
- SUSE update for jdom2
- XML External Entity injection in Oracle Healthcare Foundation
- SUSE update for jdom
- XML external entity injection in IBM Maximo Asset Management
- XML external entity injection in IBM Common Licensing
- XML external entity injection in IBM Spectrum Protect Backup-Archive Client, IBM Spectrum Protect for Virtual Environments and IBM Spectrum Protect for Space Management
- XML external entity injection in IBM Engineering Test Management (ETM)
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Oracle Service Bus
- Multiple vulnerabilities in IBM App Connect Enterprise toolkit and IBM Integration Bus
- XML External Entity injection in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- XML External Entity injection in ITCAM for Transactions
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- XML External Entity injection in IBM Engineering Lifecycle Optimization - Publishing
- XML External Entity injection in IBM Sterling B2B Integrator
- IBM Log Analysis update for Apache Solr
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in Oracle WebCenter Portal
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- openEuler update for jdom2
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Amazon Linux AMI update for jdom
- Multiple vulnerabilities in IBM Security Verify Governance
- IBM Jazz Foundation update for JDOM
- Fedora 35 update for jdom2
- Fedora 35 update for jdom
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Jira Service Management Data Center and Server update for jdom
- Jira Data Center and Jira Software Server update for jdom
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in IBM Jazz for Service Management
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for JDOM
- Multiple vulnerabilities in Siebel CRM Deployment
- Multiple vulnerabilities in Siebel CRM Integration
- IBM Content Navigator update for JDOM