Input validation error in Spring Framework - CVE-2021-22060
Published: June 3, 2022
Vulnerability identifier: #VU63976
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22060
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to modify existing log records.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and modify existing log records.
Affected software
Spring Framework
watsonx.data
IBM Qradar SIEM
IBM Cognos Controller
IBM Rational Build Forge
IBM Common Licensing
Autodesk Infraworks
IBM MaaS360 Mobile Enterprise Gateway
IBM MaaS360 Cloud Extender Agent
IBM Sterling B2B Integrator
IBM Security Verify Governance
IBM Engineering Requirements Management DOORS Next
Storage Copy Data Management
Storage Protect Plus Server
IBM MaaS360 VPN Module
watsonx.data
IBM Qradar SIEM
IBM Cognos Controller
IBM Rational Build Forge
IBM Common Licensing
Autodesk Infraworks
IBM MaaS360 Mobile Enterprise Gateway
IBM MaaS360 Cloud Extender Agent
IBM Sterling B2B Integrator
IBM Security Verify Governance
IBM Engineering Requirements Management DOORS Next
Storage Copy Data Management
Storage Protect Plus Server
IBM MaaS360 VPN Module
How to mitigate CVE-2021-22060
Install updates from vendor's website.
Spring Framework - addressed in versions 5.2.19, 5.3.14
watsonx.data - update to 2.1
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 12, 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
IBM Rational Build Forge - update to 8.0.0.29
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Storage Copy Data Management - update to 2.2.23.0
IBM MaaS360 Mobile Enterprise Gateway - update to 2.106.500
IBM MaaS360 VPN Module - update to 2.106.500
IBM MaaS360 Cloud Extender Agent - update to 2.106.500.011
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.6, 6.1.1.2, 6.1.2.0
IBM Security Verify Governance - update to 10.0.2.0.2
Storage Protect Plus Server - update to 10.1.16.1
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
watsonx.data - update to 2.1
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 12, 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
IBM Rational Build Forge - update to 8.0.0.29
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Storage Copy Data Management - update to 2.2.23.0
IBM MaaS360 Mobile Enterprise Gateway - update to 2.106.500
IBM MaaS360 VPN Module - update to 2.106.500
IBM MaaS360 Cloud Extender Agent - update to 2.106.500.011
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.6, 6.1.1.2, 6.1.2.0
IBM Security Verify Governance - update to 10.0.2.0.2
Storage Protect Plus Server - update to 10.1.16.1
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
External References
Related Security Bulletins
- Multiple vulnerabilities in IBM Common Licensing
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender Agent, Mobile Enterprise Gateway and VPN Module
- Multiple vulnerabilities in IBM QRadar SIEM
- Input validation error in IBM Sterling B2B Integrator
- Multiple vulnerabilities in Autodesk InfraWorks
- Multiple vulnerabilities in IBM Cognos Controller
- Multiple vulnerabilities in IBM Storage Protect Plus Server
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS and DOORS Web Access