Improper Restriction of Rendered UI Layers or Frames in Swagger UI - CVE-2021-46708
Published: June 7, 2022
Vulnerability identifier: #VU64013
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-46708
CWE-ID: CWE-1021
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim into opening a specially crafted URL to hijack the victim's click actions and possibly launch further attacks against the victim.
Affected software
Swagger UI
IBM Cloud Transformation Advisor
IBM IoT MessageSight
IBM WIoTP MessageGateway
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management Monitoring
IBM Sterling Partner Engagement Manager
IBM Cloud Pak for Business Automation
IBM Watson Machine Learning Accelerator
Rational Asset Analyzer
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Copy Services Manager
IBM Cognos Controller
IBM Cloud Transformation Advisor
IBM IoT MessageSight
IBM WIoTP MessageGateway
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management Monitoring
IBM Sterling Partner Engagement Manager
IBM Cloud Pak for Business Automation
IBM Watson Machine Learning Accelerator
Rational Asset Analyzer
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Copy Services Manager
IBM Cognos Controller
How to mitigate CVE-2021-46708
Install updates from vendor's website.
Swagger UI - update to 4.1.3
IBM Cloud Transformation Advisor - update to 3.1.0
IBM Watson Machine Learning Accelerator - update to 2.3.4
IBM WIoTP MessageGateway - update to 5.0.0.2
Netcool Operations Insight - update to 1.6.7
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
IBM Copy Services Manager - update to 6.3.2
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.25, 23.0.1.3
IBM Cloud Transformation Advisor - update to 3.1.0
IBM Watson Machine Learning Accelerator - update to 2.3.4
IBM WIoTP MessageGateway - update to 5.0.0.2
Netcool Operations Insight - update to 1.6.7
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
IBM Copy Services Manager - update to 6.3.2
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.25, 23.0.1.3
External References
Related Security Bulletins
- Multiple vulnerabilities in IBM WIoTP MessageGateway/IoT MessageSight
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Copy Services Manager
- Multiple vulnerabilities in IBM Cognos Controller
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in IBM Rational Asset Analyzer (RAA)