IBM Support

JR64138: SECURITY APAR - CVE-2021-35516, CVE-2021-35517, CVE-2021-35515, CVE-2021-36090 - VULNERABILITIES WITH EMBEDDED NAVIGATOR

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • CVEID:   CVE-2021-35516
    DESCRIPTION:   Apache Commons Compress is vulnerable to a denial
    of service, caused by an out of memory error when allocate large
    amounts of memory. By persuading a victim to open a
    specially-crafted 7Z archive, a remote attacker could exploit
    this vulnerability to cause a denial of service condition
    against services that use Compress' sevenz package.
    CVSS Base score: 5.5
    CVSS Temporal Score: See:
    https://exchange.xforce.ibmcloud.com/vulnerabilities/205306 for
    the current score.
    CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
    
    CVEID:   CVE-2021-35517
    DESCRIPTION:   Apache Commons Compress is vulnerable to a denial
    of service, caused by an out of memory error when allocate large
    amounts of memory. By persuading a victim to open a
    specially-crafted TAR archive, a remote attacker could exploit
    this vulnerability to cause a denial of service condition
    against services that use Compress' tar package.
    CVSS Base score: 5.5
    CVSS Temporal Score: See:
    https://exchange.xforce.ibmcloud.com/vulnerabilities/205307 for
    the current score.
    CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
    
    CVEID:   CVE-2021-35515
    DESCRIPTION:   Apache Commons Compress is vulnerable to a denial
    of service, caused by an infinite loop flaw in the construction
    of the list of codecs that decompress an entry. By persuading a
    victim to open a specially-crafted 7Z archive, a remote attacker
    could exploit this vulnerability to cause a denial of service
    condition against services that use Compress' sevenz package.
    CVSS Base score: 5.5
    CVSS Temporal Score: See:
    https://exchange.xforce.ibmcloud.com/vulnerabilities/205304 for
    the current score.
    CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
    
    CVEID:   CVE-2021-36090
    DESCRIPTION:   Apache Commons Compress is vulnerable to a denial
    of service, caused by an out of memory error when allocate large
    amounts of memory. By persuading a victim to open a
    specially-crafted ZIP archive, a remote attacker could exploit
    this vulnerability to cause a denial of service condition
    against services that use Compress' zip package.
    CVSS Base score: 5.5
    CVSS Temporal Score: See:
    https://exchange.xforce.ibmcloud.com/vulnerabilities/205310 for
    the current score.
    CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
    
    PRODUCTS AFFECTED
    IBM Business Automation Workflow
    

Local fix

Problem summary

  • No additional information is available.
    

Problem conclusion

  • A fix is available or will be available that resolves the
    multiple vulnerabilities with the embedded IBM Content Navigator
     in Business Automation Workflow.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR64138

  • Reported component name

    BUS AUTO WORKFL

  • Reported component ID

    5737H4100

  • Reported release

    K00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-09-17

  • Closed date

    2021-12-17

  • Last modified date

    2021-12-17

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    BUS AUTO WORKFL

  • Fixed component ID

    5737H4100

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS8JB4","label":"IBM Business Automation Workflow"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"20.0.0.1"}]

Document Information

Modified date:
18 December 2021