IBM Support

LI82252: CAPTCHA REPLAY VULNERABILITY

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • It was observed that the captcha submitted is not destroyed
    after being validated once by the server, allowing the user to
    replay the request using the same captcha An attacker can take
    advantage of this to brute force the application using automated
    scanners to spam the legitimate user email with password reset
    links and bruteforce the login page of the application please
    find attached more details
    

Local fix

Problem summary

  • It was found it was possible to reuse a captcha on one of the
    portal forms 4 times before it was rejected. They should be
    single use only, and are so via the UI, but using a tool such as
    cURL it was possible to replay the captcha 4 times.
    This has been fixed so they are truely single use only.
    

Problem conclusion

  • <span style="background-color:rgb(255, 255, 255)">Fixed in
    2018.4.1.17, 10.0.1.5</span>
    Fix also targeted for 10.0.4.
    

Temporary fix

Comments

APAR Information

  • APAR number

    LI82252

  • Reported component name

    API CONNECT ENT

  • Reported component ID

    5725Z2201

  • Reported release

    18X

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-07-23

  • Closed date

    2021-11-26

  • Last modified date

    2021-11-26

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    API CONNECT ENT

  • Fixed component ID

    5725Z2201

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSMNED","label":"IBM API Connect"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"18X"}]

Document Information

Modified date:
27 November 2021