Improper access control in Jetty - CVE-2021-34429

 

Improper access control in Jetty - CVE-2021-34429

Published: September 30, 2021 / Updated: November 25, 2021


Vulnerability identifier: #VU56964
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:A/U:Green
CVE-ID: CVE-2021-34429
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Affected software:
Jetty
Sterling Connect:Direct Browser User Interface
Rational Change
Oracle Financial Services Crime and Compliance Management Studio
Oracle Business Process Management Suite
Stream Analytics
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Unified Data Repository
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Binding Support Function
IBM Sterling Secure Proxy
Oracle Communications Diameter Signaling Router
IBM Customer and Network Analytics for Communications Service Providers and Datasets
Netcool Operations Insight
IBM MaaS360 Mobile Enterprise Gateway
IBM Sterling B2B Integrator
Dell NetWorker Virtual Edition
IBM Analytic Accelerator Framework for Communication Service Providers
IBM Qradar SIEM
AMQ Broker
AMQ Streams
Rational Performance Tester
Oracle Data Integrator
SUSE Linux Enterprise Module for Development Tools
Anolis OS
Oracle Retail EFTLink
Oracle Autovue for Agile Product Lifecycle Management
jetty-javadoc
jetty-continuation
jetty-jaas
jetty-io
jetty-http
jetty
jetty-client
jetty-jmx
jetty-security
jetty-server
jetty-servlet
jetty-util
jetty-util-ajax
jetty-webapp
jetty-xml
IBM InfoSphere Information Server
Oracle REST Data Services

Detailed vulnerability description

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper input validation when processing certain characters in URI. A remote attacker can send a specially crafted HTTP request with encoded characters in URI, bypass implemented security restrictions and access content of the WEB-INF directory.


How to mitigate CVE-2021-34429

Install updates from vendor's website.

Sources