PT-2022-10229 · Unknown+1 · Watsonwebserver+1

Cheng Xu

+6

·

Published

2022-05-16

·

Updated

2023-08-08

·

CVE-2021-33318

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WatsonWebserver versions 4.1.3 and below IpMatcher versions 1.0.4.1 and below
Description An Input Validation issue exists due to insufficient validation of input IP addresses and netmasks against the internal Matcher list of IP addresses and subnets.
Recommendations For WatsonWebserver versions 4.1.3 and below, update to a version above 4.1.3 to resolve the issue. For IpMatcher versions 1.0.4.1 and below, update to a version above 1.0.4.1 to resolve the issue. As a temporary workaround, consider restricting the input of IP addresses and netmasks to minimize the risk of exploitation.

Exploit

Fix

Incorrect Type Conversion or Cast

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-33318
GHSA-QJ93-37F5-MR29

Affected Products

Ipmatcher
Watsonwebserver