Rewterz
Rewterz Threat Alert – APT Group GhostWriter/UNC1151 Targeting Ukraine – Active IOCs – Russian-Ukrainian Cyber Warfare
March 10, 2022
Rewterz
Rewterz Threat Advisory – CVE-2022-24397 – SAP NetWeaver Enterprise Portal Vulnerability
March 11, 2022

Rewterz Threat Advisory – IBM Guardium Data And DataPower Gateway Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2021-39025

IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 could disclose internal IP address information when the web backend is down.

CVE-2021-39022

IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software.

CVE-2021-38910

IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused by the improper validation of input. By sending a specially crafted JSON message, an attacker could exploit this vulnerability to modify structure and fields.

Impact

  • Information Disclsoure
  • Security Bypass

Indicators Of Compromise

CVE

  • CVE-2021-39025
  • CVE-2021-39022
  • CVE-2021-38910

Affected Vendors

IBM

Affected Products

  • IBM Security Guardium Data Encryption 4.0.0.0
  • IBM Security Guardium Data Encryption 5.0.0.0
  • IBM DataPower Gateway 2018.4.1.0
  • IBM DataPower Gateway 10.0.1.0
  • IBM DataPower Gateway 10.0.2.0
  • IBM DataPower Gateway 10.0.1.5

Remediation

Refer to IBM Security Bulletin for patch, upgrade or suggested workaround information.

CVE-2021-39025
CVE-2021-39022
CVE-2021-38910