• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • IBM Patches Nine Security Flaws in IBM i

    September 29, 2021 Alex Woodie

    IBM patched issued three security bulletins Friday alerting IBM i users to the availability of patches for nine newly disclosed security vulnerabilities in OpenSSL, HTTP Server, and a WebSphere Liberty components. Some of the vulnerabilities are potentially serious and should be patched immediately.

    IBM patched two security flaws its OpenSSL API that potentially could have devastating consequences on impacted systems, including enabling a hacker to take over the server, to read sensitive information, and execute a denial of service (DOS) attack. IBM patched these flaws in IBM i 7.1 through 7.4, according to the security bulletin, which you can read here. (The fact that IBM patched 7.1 is telling, considering it’s no longer under mainstream support. However, IBM committed to supporting 7.1 through 2024 under its Program Support Extension [PSE] program in October 2020.)

    The most critical of these two OpenSSL vulnerabilities is CVE-2021-3711 which is a buffer overflow error caused by improper bounds checking. An attacker could exploit this flaw in the SM2 elliptic curve algorithm by sending a specially crafted packet, thereby overflowing the buffer and enabling the execution of arbitrary code. This flaw carries a CVSS base score of 9.8, making it a particularly dangerous vulnerability that should be patched immediately.

    IBM also patched CVE-2021-3712, which is a flaw in the Abstract Syntax Notation One (ASN.1) string structure that OpenSSL uses to serialize and deserialize data in a cross-platform manner. By sending specially crafted data, an attacker could exploit this vulnerability to read contents of memory on the system or perform a DOS attack, IBM says. This flaw carries a CVSS base score of 6.5.

    IBM patched five flaws in the HTTP Server (the one powered by Apache) that could lead to DOS attacks, enable a hacker to bypass security measures, launch Web cache poisoning or cross-site scripting attacks, and have other negative consequences for a user. IBM patched the five security vulnerabilities in IBM i versions 7.2 through 7.4. You can access this security bulletin here.

    The most severe of the HTTP Server vulnerabilities is CVE-2021-33193, which is a flaw in the HTTPd and HTTP/2 libraries that carries a CVSS base score of 6.1, making it a moderate threat. The other flaws that IBM patched, including CVE-2021-31618, CVE-2020-13950, CVE-2019-17567, and CVE-2021-30641 carry CVSS base scores of between 3.7 and 5.9.

    IBM patched two flaws in the Apache Commons Compress library, which is used by WebSphere Application Server Liberty on IBM i. The patches apply to IBM i versions 7.2 through 7.3, according to the security bulletin, which you can read here.

    The more severe of the two patched flaws is CVE-2021-36090, which is caused by an out-of-memory error that can be triggered with a specially crafted ZIP archive. This vulnerability can be exploited by a remote attacker to cause a DOS attack. It was given a CVSS base score of 7.5, which means it’s a medium-to-high threat.

    A similar flaw, CVE-2021-35517 is caused by an out-of-memory error that can be exploited with a malicious TAR archive. It can also be used to launch a DOS attack, and carries a CVSS base score of 5.5.

    Patches were issued for these nine vulnerabilities on September 24. One week earlier, IBM patched another security flaw in DHCPd, the daemon for the Dynamic Host Configuration Protocol, which is part of IBM i’s networking stack. The patch was for IBM i 7.1 through 7.4, according to the security bulletin. The specific flaw, CVE-2021-25217, is a buffer overflow that could enable an attacker to crash a DHCP server or a client. It was given a CVSS base score of 6.5.

    As always, you can find out which particular PTFs you need to apply by reading Doug Bidwell’s PTF Guide, which is published most Wednesdays in The Four Hundred. To read this week’s PTF Guide, click here.

    RELATED STORIES

    Keeping Up With Open Source Security Updates

    Locking Down Exit Point And IFS Vulnerabilities On IBM i

    Weighing The Hidden Costs Of Open Source

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags: Tags: Apache Commons Compress, API, CVSS, DHCPd, DOS, Dynamic Host Configuration Protocol, HTTP, HTTP/2, HTTPd, IBM i, OpenSSL, Program Support Extension, PSE, PTF, WebSphere Application Server Liberty, WebSphere Liberty

    Sponsored by
    New Generation Software

    FREE Webinar:

    Creating Great Data for Enterprise AI

    Enterprise AI relies on many data sources and types, but every AI project needs a data quality, governance, and security plan.

    Wherever and however you want to analyze your data, adopting modern ETL and BI software like NGS-IQ is a great way to support your effort.

    Webinar: June 26, 2025

    RSVP today.

    www.ngsi.com – 800-824-1220

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    The IBM i And Its RPG Decade Of Crisis Rocket Maps IBM i Apps for Modernization Ventures

    One thought on “IBM Patches Nine Security Flaws in IBM i”

    • Bob Losey says:
      September 29, 2021 at 10:22 am

      Excelent! I always enjoy your articles

      Reply

    Leave a Reply Cancel reply

TFH Volume: 31 Issue: 63

This Issue Sponsored By

  • Maxava
  • Eradani
  • ASNA
  • LANSA
  • UCG Technologies

Table of Contents

  • Rocket Maps IBM i Apps for Modernization Ventures
  • IBM Patches Nine Security Flaws in IBM i
  • The IBM i And Its RPG Decade Of Crisis
  • Four Hundred Monitor, September 29
  • IBM i PTF Guide, Volume 23, Number 39

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Big Blue Raises IBM i License Transfer Fees, Other Prices
  • Keep The IBM i Youth Movement Going With More Training, Better Tools
  • Remain Begins Migrating DevOps Tools To VS Code
  • IBM Readies LTO-10 Tape Drives And Libraries
  • IBM i PTF Guide, Volume 27, Number 23
  • SEU’s Fate, An IBM i V8, And The Odds Of A Power13
  • Tandberg Bankruptcy Leaves A Hole In IBM Power Storage
  • RPG Code Generation And The Agentic Future Of IBM i
  • A Bunch Of IBM i-Power Systems Things To Be Aware Of
  • IBM i PTF Guide, Volume 27, Numbers 21 And 22

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle