Insufficient verification of data authenticity in Apache Commons Net - CVE-2021-37533

 

Insufficient verification of data authenticity in Apache Commons Net - CVE-2021-37533

Published: December 20, 2022


Vulnerability identifier: #VU70441
CSH Severity: Low
CVSS v4 BT: 0.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-37533
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to redirect victim to a malicious host.

The vulnerability exists due to the application trusts the host from PASV response by default. A remote attacker can trick the victim into connecting to an attacker controlled FTP server and then redirect the application to another host.


Affected software

Apache Commons Net
Oracle Agile PLM Framework
Red Hat Camel for Spring Boot
IBM App Connect Enterprise
IBM Qradar SIEM
Oracle Analytics Desktop
Oracle FLEXCUBE Core Banking
Cloud Pak for Security (CP4S)
Jazz Reporting Service
IBM Cognos Command Center
IBM Business Automation Workflow
IBM Observability with Instana
Red Hat Integration Camel Extensions for Quarkus
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Intelligent Operations Center
Dell Secure Connect Gateway
IBM Sterling B2B Integrator
Oracle Communications Network Integrity
Oracle Communications IP Service Activator
Oracle Financial Services Model Management and Governance
IBM MQ
Oracle Communications Session Report Manager
Oracle Identity Manager Connector
Middleware Common Libraries and Tools
Oracle Middleware Common Libraries and Tools
Enterprise Manager Base Platform
Oracle Banking Trade Finance
Oracle Banking Treasury Management
Oracle Communications EAGLE Element Management System
Netcool Operations Insight
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Tivoli Business Service Manager
IBM Sterling Connect:Direct Web Services
UCD - IBM UrbanCode Deploy
IBM Tivoli Netcool Impact
Tivoli Composite Application Manager for Transactions
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
Maximo Manage Application in IBM Maximo Application Suite
IBM Integration Bus
Debian Linux
Oracle Solaris Cluster
Ubuntu
openEuler
ObjectScale
Analytics Content Hub
Cognos Dashboards on Cloud Pak for Data
DataStage on Cloud Pak for Data
Oracle Business Intelligence Enterprise Edition
IBM Engineering Requirements Management DOORS Next
Oracle Data Integrator
Oracle FLEXCUBE Universal Banking
Oracle Retail Service Backbone
Oracle FLEXCUBE Investor Servicing
Dell EMC Streaming Data Platform
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
User Entity Behavior Analytics
Integration Bus for z/OS
IBM Data Risk Manager
Cloudera Data Platform Private Cloud Base for IBM
Oracle Communications Element Manager
Identity Manager Connector
Siebel Apps
IBM Cloud Pak System
SecureTransport
Communications Service Catalog and Design
Oracle Communications Offline Mediation Controller
Oracle Communications Billing and Revenue Management
PeopleSoft Enterprise PeopleTools
Oracle Documaker
PeopleSoft Enterprise CRM Client Management
Oracle Commerce Guided Search
Oracle Banking Payments
Oracle WebCenter Content
Oracle Banking Corporate Lending
Oracle Retail Integration Bus
Primavera Gateway
OSS Support Tools
IBM Disconnected Log Collector
libcommons-net-java (Ubuntu package)
libcommons-net-java (Debian package)
apache-commons-net
apache-commons-net-help
IBM InfoSphere Information Server

How to mitigate CVE-2021-37533

Install updates from vendor's website.

Apache Commons Net - update to 3.9.0
ObjectScale - update to 1.3.0
Analytics Content Hub - update to 2.2
IBM Data Risk Manager - update to 2.0.6.17
IBM Cloud Pak System - update to 2.3.3.6
Red Hat Integration Camel Extensions for Quarkus - update to 2.13.3
Cognos Dashboards on Cloud Pak for Data - update to 4.8.0
DataStage on Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
IBM Intelligent Operations Center - update to 5.2.4
SecureTransport - update to 5.5-20230126
Dell Secure Connect Gateway - addressed in versions 5.16, 5.28.00.14
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
IBM MQ - addressed in versions 9.0.0.14, 9.1.0.13, 9.2.0.8, 9.3.0.3, 9.3.1.1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Oracle FLEXCUBE Core Banking - update to 11.8.0
Oracle Banking Corporate Lending - update to 14.4
Oracle Banking Trade Finance - update to 14.4
Oracle FLEXCUBE Universal Banking - update to 14.7.0.0.0
libcommons-net-java (Ubuntu package) - addressed in versions Ubuntu Pro, 3.6-1+deb11u1build0.18.04.1, 3.6-1+deb11u1build0.20.04.1, 3.6-1+deb11u1build0.22.04.1, 3.6-1+deb11u1build0.22.10.1
Netcool Operations Insight - update to 1.6.10
Dell EMC Streaming Data Platform - update to 1.7.0
IBM Disconnected Log Collector - update to 1.8.3
Cloud Pak for Security (CP4S) - update to 1.10.8.0
Cloud Pak for Network Automation - update to 2.4.4
libcommons-net-java (Debian package) - update to 3.6-1+deb11u1
apache-commons-net - update to 3.6-7
apache-commons-net-help - update to 3.6-7
Red Hat Camel for Spring Boot - update to 3.20.1
QRadar User Behavior Analytics - update to 4.1.12
IBM Cloud Pak for Watson AIOps - update to 4.6.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
User Entity Behavior Analytics - update to 5.0.2
App Connect Enterprise Certified Container - addressed in versions 5.0.6, 8.1.0
IBM Tivoli Business Service Manager - update to 6.2.0.5.3
IBM Sterling Connect:Direct Web Services - addressed in versions 6.2.0.18, 6.3.0.2
UCD - IBM UrbanCode Deploy - addressed in versions 6.2.7.20, 7.0.5.15, 7.1.2.11, 7.2.3.4, 7.3.1.0
Jazz Reporting Service - update to 7.0.2 iFix024
IBM Tivoli Netcool Impact - update to 7.1.0.29
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
IBM Maximo Asset Management - addressed in versions 7.6.1.2.33, 7.6.1.3.8
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.4.9, 8.5.5
IBM Integration Bus - addressed in versions 10.0.0.26, 10.1
Integration Bus for z/OS - update to 10.1.0.3
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
IBM App Connect Enterprise - addressed in versions 11.0.0.20, 12.0.8.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

External References

Related Security Bulletins