Improper input validation in Oracle REST Data Services - CVE-2020-27223

 

Improper input validation in Oracle REST Data Services - CVE-2020-27223

Published: April 21, 2021 / Updated: November 16, 2023


Vulnerability identifier: #VU52385
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27223
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The vulnerability exists due to improper input validation within the General (Eclipse Jetty) component in Oracle REST Data Services. A remote non-authenticated attacker can exploit this vulnerability to perform service disruption.


Affected software

Oracle REST Data Services
IBM App Connect Enterprise
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
cri-o (Red Hat package)
jenkins (Red Hat package)
python-requests (Red Hat package)
atomic-openshift (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-cluster-autoscaler (Red Hat package)
golang-github-prometheus-alertmanager (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-openshift-metrics-server (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
openshift-enterprise-autoheal (Red Hat package)
atomic-openshift-web-console (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
openshift-enterprise-cluster-capacity (Red Hat package)
golang-github-openshift-oauth-proxy (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
atomic-openshift-dockerregistry (Red Hat package)
openshift-kuryr (Red Hat package)
jenkins-2-plugins (Red Hat package)
openshift (Red Hat package)
machine-config-daemon (Red Hat package)
openshift-clients (Red Hat package)
jetty9 (Debian package)
jetty-cdi
jetty-deploy
jetty-proxy
jetty-util-ajax
jetty-http2-common
jetty-webapp
jetty-websocket-common
jetty-osgi-boot-warurl
jetty-jstl
jetty-http
jetty-fcgi-client
jetty-websocket-client
jetty-websocket-api
jetty-rewrite
jetty-plus
jetty-httpservice
jetty-jsp
jetty-security
jetty-alpn-server
jetty-quickstart
jetty-jaspi
jetty-http2-server
jetty-client
jetty-alpn-client
jetty-jaas
jetty-jmx
jetty-annotations
jetty-http2-hpack
jetty-jspc-maven-plugin
jetty-websocket-server
jetty-start
jetty-unixsocket
jetty-server
jetty-servlet
jetty
jetty-http-spi
jetty-websocket-servlet
jetty-javadoc
jetty-javax-websocket-client-impl
jetty-xml
jetty-io
jetty-maven-plugin
jetty-osgi-boot
jetty-osgi-boot-jsp
jetty-continuation
jetty-infinispan
jetty-http2-http-client-transport
jetty-fcgi-server
jetty-util
jetty-javax-websocket-server-impl
jetty-servlets
jetty-jndi
jetty-http2-client
jetty-project
jetty-nosql
jetty-ant
jetty-spring
jetty-osgi-alpn
Cloudera Data Platform Private Cloud Base for IBM
AMQ Broker
Fuse
IBM Integration Bus
Red Hat Integration Camel-K
IBM Process Mining
Unified Mediation Bus
IBM Security Verify Governance
SUSE Linux Enterprise Module for Development Tools
openEuler
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Engineering Systems Design Rhapsody
webMethods BPM
Dell Security Management Server
IBM Cognos Command Center

How to mitigate CVE-2020-27223

Install updates from vendor's website.

Oracle REST Data Services - update to 20.4.3.050.1904
Migration Toolkit for Containers - update to 1.4.6
cri-o (Red Hat package) - addressed in versions 1.19.2-6.rhaos4.6.git686e6d9.el7, 1.19.2-6.rhaos4.6.git686e6d9.el8
jenkins (Red Hat package) - addressed in versions 2.277.3.1623846768-1.el7, 2.277.3.1623853726-1.el8, 2.289.1.1624365627-1.el7
python-requests (Red Hat package) - update to 2.19.1-5.el7
Red Hat OpenShift Container Platform - addressed in versions 3.11.462, 4.5.41, 4.6.36
atomic-openshift (Red Hat package) - update to 3.11.462-1.git.0.e7d0362.el7
openshift-ansible (Red Hat package) - addressed in versions 3.11.462-1.git.0.53e69e6.el7, 4.5.0-202106011407.p0.git.83db419.el7
atomic-openshift-cluster-autoscaler (Red Hat package) - update to 3.11.462-1.git.99b2acf.el7
golang-github-prometheus-alertmanager (Red Hat package) - update to 3.11.462-1.git.13de638.el7
atomic-openshift-service-idler (Red Hat package) - addressed in versions 3.11.462-1.git.39cfc66.el7, 4.5.0-202106011407.p0.git.39cfc66.el7
atomic-openshift-metrics-server (Red Hat package) - update to 3.11.462-1.git.f8bf728.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.11.462-1.git.c8f26da.el7
openshift-enterprise-autoheal (Red Hat package) - update to 3.11.462-1.git.f2f435d.el7
atomic-openshift-web-console (Red Hat package) - update to 3.11.462-1.git.656f5d6.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.11.462-1.git.d435537.el7
openshift-enterprise-cluster-capacity (Red Hat package) - update to 3.11.462-1.git.22be164.el7
golang-github-openshift-oauth-proxy (Red Hat package) - update to 3.11.462-1.git.edebe84.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.11.462-1.git.609cd20.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 3.11.462-1.git.2e6be86.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 3.11.462-1.git.99aae51.el7
atomic-openshift-dockerregistry (Red Hat package) - update to 3.11.462-1.git.3571208.el7
openshift-kuryr (Red Hat package) - addressed in versions 3.11.462-1.git.c33a657.el7, 4.5.0-202106011407.p0.git.75cc301.el8, 4.6.0-202106181055.p0.git.7feb5bd.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 3.11.1624366838-1.el7, 4.5.1623326336-1.el7
openshift (Red Hat package) - addressed in versions 4.5.0-202106011407.p0.git.d8ef5ad.el7, 4.5.0-202106011407.p0.git.d8ef5ad.el8
machine-config-daemon (Red Hat package) - update to 4.5.0-202106011407.p0.git.f003424.el8
openshift-clients (Red Hat package) - addressed in versions 4.5.0-202106011407.p0.git.297a4ac.el7, 4.5.0-202106011407.p0.git.297a4ac.el8, 4.6.0-202106160917.p0.git.99556b6.el7, 4.6.0-202106160917.p0.git.99556b6.el8
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.9.3 HF2
AMQ Broker - addressed in versions 7.8.2, 7.9.0
jetty9 (Debian package) - update to 9.4.16-0+deb10u1
Red Hat Integration Camel-K - update to 1.8
IBM Process Mining - update to 1.12.0.4
Unified Mediation Bus - update to 4.4
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
Fuse - update to 7.10.0
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
jetty-cdi - update to 9.4.15-7
jetty-deploy - update to 9.4.15-7
jetty-proxy - update to 9.4.15-7
jetty-util-ajax - update to 9.4.15-7
jetty-http2-common - update to 9.4.15-7
jetty-webapp - update to 9.4.15-7
jetty-websocket-common - update to 9.4.15-7
jetty-osgi-boot-warurl - update to 9.4.15-7
jetty-jstl - update to 9.4.15-7
jetty-http - update to 9.4.15-7
jetty-fcgi-client - update to 9.4.15-7
jetty-websocket-client - update to 9.4.15-7
jetty-websocket-api - update to 9.4.15-7
jetty-rewrite - update to 9.4.15-7
jetty-plus - update to 9.4.15-7
jetty-httpservice - update to 9.4.15-7
jetty-jsp - update to 9.4.15-7
jetty-security - update to 9.4.15-7
jetty-alpn-server - update to 9.4.15-7
jetty-quickstart - update to 9.4.15-7
jetty-jaspi - update to 9.4.15-7
jetty-http2-server - update to 9.4.15-7
jetty-client - update to 9.4.15-7
jetty-alpn-client - update to 9.4.15-7
jetty-jaas - update to 9.4.15-7
jetty-jmx - update to 9.4.15-7
jetty-annotations - update to 9.4.15-7
jetty-http2-hpack - update to 9.4.15-7
jetty-jspc-maven-plugin - update to 9.4.15-7
jetty-websocket-server - update to 9.4.15-7
jetty-start - update to 9.4.15-7
jetty-unixsocket - update to 9.4.15-7
jetty-server - update to 9.4.15-7
jetty-servlet - update to 9.4.15-7
jetty - update to 9.4.15-7
jetty-http-spi - update to 9.4.15-7
jetty-websocket-servlet - update to 9.4.15-7
jetty-javadoc - update to 9.4.15-7
jetty-javax-websocket-client-impl - update to 9.4.15-7
jetty-xml - update to 9.4.15-7
jetty-io - update to 9.4.15-7
jetty-maven-plugin - update to 9.4.15-7
jetty-osgi-boot - update to 9.4.15-7
jetty-osgi-boot-jsp - update to 9.4.15-7
jetty-continuation - update to 9.4.15-7
jetty-infinispan - update to 9.4.15-7
jetty-http2-http-client-transport - update to 9.4.15-7
jetty-fcgi-server - update to 9.4.15-7
jetty-util - update to 9.4.15-7
jetty-javax-websocket-server-impl - update to 9.4.15-7
jetty-servlets - update to 9.4.15-7
jetty-jndi - update to 9.4.15-7
jetty-http2-client - update to 9.4.15-7
jetty-project - update to 9.4.15-7
jetty-nosql - update to 9.4.15-7
jetty-ant - update to 9.4.15-7
jetty-spring - update to 9.4.15-7
jetty-osgi-alpn - update to 9.4.15-7
jetty-util-ajax - update to 9.4.38-3.6.2
jetty-util - update to 9.4.38-3.6.2
jetty-servlet - update to 9.4.38-3.6.2
jetty-server - update to 9.4.38-3.6.2
jetty-security - update to 9.4.38-3.6.2
jetty-io - update to 9.4.38-3.6.2
jetty-http - update to 9.4.38-3.6.2
IBM Security Verify Governance - update to 10.0.1.0.3
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
webMethods BPM - addressed in versions 10.15 Fix 15, 11.1 Fix 3
Dell Security Management Server - update to 11.1.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins