Improper input validation in Oracle Communications Cloud Native Core Policy - CVE-2021-3200

 

Improper input validation in Oracle Communications Cloud Native Core Policy - CVE-2021-3200

Published: April 22, 2022


Vulnerability identifier: #VU62515
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3200
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to perform service disruption.

The vulnerability exists due to improper input validation within the Signaling (libsolv) component in Oracle Communications Cloud Native Core Policy. A local non-authenticated attacker can exploit this vulnerability to perform service disruption.


Affected software

Oracle Communications Cloud Native Core Policy
Amazon Linux AMI
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
openEuler
Cloud Pak for Security (CP4S)
Business Automation Insights
IBM Cloud Pak for Business Automation
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
libsolv-devel
libsolv-tools
libsolv-tools-debuginfo
libsolv-debugsource
perl-solv
perl-solv-debuginfo
python-solv
python-solv-debuginfo
libsolv-devel-debuginfo
libsolv-help
python3-solv
ruby-solv
libsolv-debuginfo
libsolv
libsolv (Red Hat package)
libzypp-devel
libzypp-debugsource
libzypp-debuginfo
libzypp
libzypp-devel-doc
Migration Toolkit for Containers
Red Hat OpenShift Serverless

How to mitigate CVE-2021-3200

Install updates from vendor's website.

Cloud Pak for Security (CP4S) - update to 1.10.7.0
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
libsolv-devel - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-tools - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-tools-debuginfo - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-debugsource - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
perl-solv - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
perl-solv-debuginfo - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
python-solv - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
python-solv-debuginfo - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-devel-debuginfo - update to 0.6.37-2.33.1
libsolv-debugsource - update to 0.7.14-2
libsolv-help - update to 0.7.14-2
python3-solv - update to 0.7.14-2
perl-solv - update to 0.7.14-2
libsolv-devel - update to 0.7.14-2
ruby-solv - update to 0.7.14-2
libsolv-debuginfo - update to 0.7.14-2
libsolv - update to 0.7.14-2
libsolv (Red Hat package) - update to 0.7.19-1.el8
libsolv - update to 0.7.22-1
Migration Toolkit for Containers - update to 1.5.4
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Red Hat OpenStack - update to 16.2
libzypp-devel - addressed in versions 16.21.4-2.51.1, 16.21.4-27.75.1
libzypp-debugsource - addressed in versions 16.21.4-2.51.1, 16.21.4-27.75.1
libzypp-debuginfo - addressed in versions 16.21.4-2.51.1, 16.21.4-27.75.1
libzypp - addressed in versions 16.21.4-2.51.1, 16.21.4-27.75.1
libzypp-devel-doc - update to 16.21.4-2.51.1

External References

Related Security Bulletins