Input validation error in Hibernate Validator - CVE-2020-10693

 

Input validation error in Hibernate Validator - CVE-2020-10693

Published: July 6, 2022


Vulnerability identifier: #VU64945
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10693
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify files on the system.

The vulnerability exists due to insufficient validation of user-supplied input when handling user-controlled data in error messages. A remote attacker can bypass input sanitation (escaping, stripping) controls.


Affected software

Hibernate Validator
IBM Tivoli Network Manager (ITNM)
Middleware Common Libraries and Tools
Oracle Middleware Common Libraries and Tools
IBM Cloud Transformation Advisor
openEuler
watsonx.data
Storage Defender Copy Data Management
hibernate-validator
hibernate-validator-annotation-processor
hibernate-validator-cdi
hibernate-validator-performance
hibernate-validator-parent
hibernate-validator-javadoc
hibernate-validator-test-utils
RSA Authentication Manager

How to mitigate CVE-2020-10693

Install updates from vendor's website.

Hibernate Validator - addressed in versions 6.0.20, 6.1.5, 7.0.0 Alpha2
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.15
watsonx.data - update to 2.0.2
Storage Defender Copy Data Management - update to 2.2.28.0
IBM Cloud Transformation Advisor - update to 2.4.0
hibernate-validator - update to 5.2.4-3
hibernate-validator-annotation-processor - update to 5.2.4-3
hibernate-validator-cdi - update to 5.2.4-3
hibernate-validator-performance - update to 5.2.4-3
hibernate-validator-parent - update to 5.2.4-3
hibernate-validator-javadoc - update to 5.2.4-3
hibernate-validator-test-utils - update to 5.2.4-3
RSA Authentication Manager - update to 8.7 Patch 3

External References

Related Security Bulletins