Externally Controlled Reference to a Resource in Another Sphere in Kubernetes - CVE-2021-25740
Published: February 5, 2024
Vulnerability identifier: #VU86073
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-25740
CWE-ID: CWE-610
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote users can send network traffic to locations they would otherwise not have access to via a confused deputy attack.
Affected software
Kubernetes
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM InfoSphere Information Server
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM InfoSphere Information Server
How to mitigate CVE-2021-25740
Install updates from vendor's website.
Netcool Operations Insight - update to 1.6.10
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4