CVE-2021-39031: High severity ibm open liberty vulnerability
IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.
Other sources
IBM WebSphere Application Server - Liberty could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-39031?
CVE-2021-39031 is a vulnerability in IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 that could allow a remote authenticated attacker to conduct an LDAP injection.
What is the severity of CVE-2021-39031?
CVE-2021-39031 has a severity rating of 8.8 (high).
How can an attacker exploit CVE-2021-39031?
An attacker can exploit CVE-2021-39031 by using a specially crafted request to conduct an LDAP injection, potentially granting permission to unauthorized resources.
Is there a fix available for CVE-2021-39031?
Yes, IBM has provided fixes for this vulnerability. Please refer to the IBM support pages for more information on how to apply the fixes.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-39031?
CVE-2021-39031 is associated with CWE-74, which is the CWE ID for Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection').