Input validation error in Spring Framework - CVE-2021-22060

 

Input validation error in Spring Framework - CVE-2021-22060

Published: June 3, 2022


Vulnerability identifier: #VU63976
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22060
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify existing log records.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and modify existing log records.


Affected software

Spring Framework
watsonx.data
IBM Qradar SIEM
IBM Cognos Controller
IBM Rational Build Forge
IBM Common Licensing
Autodesk Infraworks
IBM MaaS360 Mobile Enterprise Gateway
IBM MaaS360 Cloud Extender Agent
IBM Sterling B2B Integrator
IBM Security Verify Governance
IBM Engineering Requirements Management DOORS Next
Storage Copy Data Management
Storage Protect Plus Server
IBM MaaS360 VPN Module

How to mitigate CVE-2021-22060

Install updates from vendor's website.

Spring Framework - addressed in versions 5.2.19, 5.3.14
watsonx.data - update to 2.1
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 12, 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
IBM Rational Build Forge - update to 8.0.0.29
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Storage Copy Data Management - update to 2.2.23.0
IBM MaaS360 Mobile Enterprise Gateway - update to 2.106.500
IBM MaaS360 VPN Module - update to 2.106.500
IBM MaaS360 Cloud Extender Agent - update to 2.106.500.011
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.6, 6.1.1.2, 6.1.2.0
IBM Security Verify Governance - update to 10.0.2.0.2
Storage Protect Plus Server - update to 10.1.16.1
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2

External References

Related Security Bulletins