IBM Support

Security Bulletin: LDAP vulnerability in WebSphere Liberty Profile can affect IBM InfoSphere Identity Insight (CVE-2021-39031)

Security Bulletin


Summary

A vulnerability in the WebSphere Liberty Profile used in IBM Identity Insight could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability only exists if the instance of Identity Insight is configured for LDAP, which would only happen as a result of manual configuration changes made by the customer to the WebSphere Liberty within Identity Insight. Normal Identity Insight installation does not configure LDAP.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s)Version(s)
IBM InfoSphere Identity Insight9.1
IBM InfoSphere Identity Insight9.0
IBM InfoSphere Identity Insight10.0

Remediation/Fixes

For Identity Insight customers who configure its WebSphere Liberty to use LDAP: Per the original bulletin for CVE-2021-39031 (https://www.ibm.com/support/pages/security-bulletin-ibm-websphere-application-server-liberty-vulnerable-ldap-injection-cve-2021-39031), this issue can be resolved by upgrading the WebSphere Liberty Profile in Identity Insight to version 22.0.0.2 or later. Instructions for updating it to version 22.0.0.4 are found in the tech note at https://www.ibm.com/support/pages/node/6574079.

For Identity Insight customers who do not configure for LDAP, there is no vulnerability and no update is necessary.

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

21 Apr 2022: Initial Publication

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS2HSB","label":"InfoSphere Identity Insight"},"Component":"","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"},{"code":"PF002","label":"AIX"}],"Version":"9.0, 9.1, 10.0","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
21 April 2022

Initial Publish date:
21 April 2022

UID

ibm16574097