Security Bulletin
Summary
A vulnerability in the WebSphere Liberty Profile used in IBM Identity Insight could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability only exists if the instance of Identity Insight is configured for LDAP, which would only happen as a result of manual configuration changes made by the customer to the WebSphere Liberty within Identity Insight. Normal Identity Insight installation does not configure LDAP.
Vulnerability Details
Refer to the security bulletin(s) listed in the Remediation/Fixes section
Affected Products and Versions
| Affected Product(s) | Version(s) |
| IBM InfoSphere Identity Insight | 9.1 |
| IBM InfoSphere Identity Insight | 9.0 |
| IBM InfoSphere Identity Insight | 10.0 |
Remediation/Fixes
For Identity Insight customers who configure its WebSphere Liberty to use LDAP: Per the original bulletin for CVE-2021-39031 (https://www.ibm.com/support/pages/security-bulletin-ibm-websphere-application-server-liberty-vulnerable-ldap-injection-cve-2021-39031), this issue can be resolved by upgrading the WebSphere Liberty Profile in Identity Insight to version 22.0.0.2 or later. Instructions for updating it to version 22.0.0.4 are found in the tech note at https://www.ibm.com/support/pages/node/6574079.
For Identity Insight customers who do not configure for LDAP, there is no vulnerability and no update is necessary.
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Change History
21 Apr 2022: Initial Publication
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
21 April 2022
Initial Publish date:
21 April 2022
UID
ibm16574097