Input validation error in Swagger UI - CVE-2018-25031

 

Input validation error in Swagger UI - CVE-2018-25031

Published: June 7, 2022 / Updated: October 25, 2024


Vulnerability identifier: #VU64011
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-25031
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim into opening a specially crafted URL to display remote OpenAPI definitions.


Affected software

Swagger UI
QRadar Pulse App
IBM Sterling Transformation Extender
IBM Concert Software
IBM Cloud Transformation Advisor
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Tivoli Netcool Impact
IBM Rational Build Forge
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow
IBM Cloud Pak for Multicloud Management Monitoring
IBM Fusion HCI
Qradar Advisor
IBM Sterling Partner Engagement Manager
IBM Rational ClearQuest
IBM i Modernization Engine for Lifecycle Integration
IBM Watson Machine Learning Accelerator
Rational Asset Analyzer
webMethods Designer Service Development
IBM Planning Analytics Workspace
IBM Edge Application Manager
IBM Copy Services Manager
IBM CICS TX Advanced
IBM CICS TX Standard
watsonx.data
IBM Cognos Controller
IBM InfoSphere Information Server

How to mitigate CVE-2018-25031

Install updates from vendor's website.

Swagger UI - update to 4.1.3
IBM Concert Software - update to 1.0.3
IBM i Modernization Engine for Lifecycle Integration - update to 1.0.1
QRadar Pulse App - update to 2.2.9
IBM Cloud Transformation Advisor - update to 3.1.0
IBM Watson Machine Learning Accelerator - update to 2.3.4
IBM WIoTP MessageGateway - update to 5.0.0.2
IBM Tivoli Netcool Impact - update to 7.1.0.25
IBM Rational Build Forge - update to 8.0.0.29
webMethods Designer Service Development - update to 11.1 Fix2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
IBM Business Automation Workflow - update to 22.0.1-IF002
IBM Planning Analytics Workspace - update to 2.0.83
watsonx.data - update to 2.1.1
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
IBM Fusion HCI - update to 2.6.1
Qradar Advisor - update to 2.6.4
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
IBM Copy Services Manager - update to 6.3.2
IBM Rational ClearQuest - update to 10.0.3
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins