Improper Restriction of Rendered UI Layers or Frames in Swagger UI - CVE-2021-46708

 

Improper Restriction of Rendered UI Layers or Frames in Swagger UI - CVE-2021-46708

Published: June 7, 2022


Vulnerability identifier: #VU64013
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-46708
CWE-ID: CWE-1021
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim into opening a specially crafted URL to hijack the victim's click actions and possibly launch further attacks against the victim.


Affected software

Swagger UI
IBM Cloud Transformation Advisor
IBM IoT MessageSight
IBM WIoTP MessageGateway
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management Monitoring
IBM Sterling Partner Engagement Manager
IBM Cloud Pak for Business Automation
IBM Watson Machine Learning Accelerator
Rational Asset Analyzer
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Copy Services Manager
IBM Cognos Controller

How to mitigate CVE-2021-46708

Install updates from vendor's website.

Swagger UI - update to 4.1.3
IBM Cloud Transformation Advisor - update to 3.1.0
IBM Watson Machine Learning Accelerator - update to 2.3.4
IBM WIoTP MessageGateway - update to 5.0.0.2
Netcool Operations Insight - update to 1.6.7
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
IBM Copy Services Manager - update to 6.3.2
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.25, 23.0.1.3

External References

Related Security Bulletins