Incorrect regular expression in nth-check - CVE-2021-3803
Published: May 16, 2023
Vulnerability identifier: #VU76185
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3803
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
nth-check
watsonx.data
watsonx Orchestrate Developer Edition
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
IBM Process Mining
Jira Service Management Data Center
Jira Software Data Center
QRadar User Behavior Analytics
Bitbucket Data Center
IBM Cloud Pak System
IBM Edge Application Manager
Splunk Enterprise
Ubuntu
node-nth-check (Ubuntu package)
Cloud Pak for Data
Bitbucket Server
watsonx.data
watsonx Orchestrate Developer Edition
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
IBM Process Mining
Jira Service Management Data Center
Jira Software Data Center
QRadar User Behavior Analytics
Bitbucket Data Center
IBM Cloud Pak System
IBM Edge Application Manager
Splunk Enterprise
Ubuntu
node-nth-check (Ubuntu package)
Cloud Pak for Data
Bitbucket Server
How to mitigate CVE-2021-3803
Install updates from vendor's website.
nth-check - update to 2.0.1
watsonx Orchestrate Developer Edition - update to 1.15.0
IBM Process Mining - update to 1.12.0.4
watsonx.data - update to 2.3.1
IBM Cloud Pak System - update to 2.3.3.6
Jira Service Management Data Center - update to 10.3.22
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Jira Software Data Center - update to 10.3.22
node-nth-check (Ubuntu package) - addressed in versions 1.0.1-1+deb10u1build0.18.04.1, 1.0.1-1+deb10u1build0.20.04.1
Cognos Analytics Mobile (iOS) - update to 1.1.20
Cognos Analytics Mobile (Android) - update to 1.1.20
QRadar User Behavior Analytics - update to 4.1.13
Cloud Pak for Data - update to 4.8.5
Bitbucket Server - update to 8.19.25
Bitbucket Data Center - update to 8.19.25
watsonx Orchestrate Developer Edition - update to 1.15.0
IBM Process Mining - update to 1.12.0.4
watsonx.data - update to 2.3.1
IBM Cloud Pak System - update to 2.3.3.6
Jira Service Management Data Center - update to 10.3.22
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Jira Software Data Center - update to 10.3.22
node-nth-check (Ubuntu package) - addressed in versions 1.0.1-1+deb10u1build0.18.04.1, 1.0.1-1+deb10u1build0.20.04.1
Cognos Analytics Mobile (iOS) - update to 1.1.20
Cognos Analytics Mobile (Android) - update to 1.1.20
QRadar User Behavior Analytics - update to 4.1.13
Cloud Pak for Data - update to 4.8.5
Bitbucket Server - update to 8.19.25
Bitbucket Data Center - update to 8.19.25
External References
Related Security Bulletins
- Regular expression denial of service in nth-check
- Incorrect regular expression in IBM Edge Application Manager
- Ubuntu update for node-nth-check
- Incorrect regular expression in IBM Process Mining
- Multiple vulnerabilities in IBM Cloud Pak System
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Incorrect regular expression in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (Android)
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (iOS)
- Bitbucket Data Center and Server update for nth-check
- IBM watsonx Orchestrate Developer Edition update for nth-check
- IBM watsonx.data update for nth-check
- Multiple vulnerabilities in Jira Service Management Data Center and Jira Service Management Server
- Multiple vulnerabilities in Jira Software Data Center