PT-2022-10229 · Unknown+1 · Watsonwebserver+1
Cheng Xu
+6
·
Published
2022-05-16
·
Updated
2023-08-08
·
CVE-2021-33318
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WatsonWebserver versions 4.1.3 and below
IpMatcher versions 1.0.4.1 and below
Description
An Input Validation issue exists due to insufficient validation of input IP addresses and netmasks against the internal Matcher list of IP addresses and subnets.
Recommendations
For WatsonWebserver versions 4.1.3 and below, update to a version above 4.1.3 to resolve the issue.
For IpMatcher versions 1.0.4.1 and below, update to a version above 1.0.4.1 to resolve the issue.
As a temporary workaround, consider restricting the input of IP addresses and netmasks to minimize the risk of exploitation.
Exploit
Fix
Incorrect Type Conversion or Cast
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ipmatcher
Watsonwebserver