A vulnerability, which was classified as critical, was found in Oracle Hospitality Suite8 8.13/8.14 (Hospitality Software). Affected is an unknown function of the component Netty. The manipulation with an unknown input leads to a information disclosure vulnerability. CWE is classifying the issue as CWE-200. This is going to have an impact on confidentiality. CVE summarizes:

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty’s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method “File.createTempFile” on unix-like systems creates a random file, but, by default will create this file with the permissions “-rw-r–r–“. Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty’s “AbstractDiskHttpData” is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own “java.io.tmpdir” when you start the JVM or use “DefaultHttpDataFactory.setBaseDir(…)” to set the directory to something that is only readable by the current user.

The weakness was published 07/20/2021 as Oracle Critical Patch Update Advisory – July 2021. The advisory is available at oracle.com. This vulnerability is traded as CVE-2021-21290 since 12/22/2020. The exploitability is told to be easy. Local access is required to approach this attack. The successful exploitation requires a authentication. The technical details are unknown and an exploit is not available. The structure of the vulnerability defines a possible price range of USD $0-$5k at the moment (estimation calculated on 07/24/2021).

Upgrading eliminates this vulnerability. A possible mitigation has been published immediately after the disclosure of the vulnerability.




Class: Information disclosure
CWE: CWE-200
ATT&CK: Unknown

Local: Yes
Remote: No

Upgrade: oracle.com

12/22/2020 CVE assigned
07/20/2021 +209 days Advisory disclosed
07/20/2021 +0 days Countermeasure disclosed
07/21/2021 +1 days VulDB entry created
Vendor: https://www.oracle.com

Advisory: Oracle Critical Patch Update Advisory – July 2021
Status: Confirmed
Created: 07/21/2021 10:37
Updated: 07/24/2021 14:10
Changes: (17) vulnerability_cvss3_nvd_av vulnerability_cvss3_nvd_ac vulnerability_cvss3_nvd_pr vulnerability_cvss3_nvd_ui vulnerability_cvss3_nvd_s vulnerability_cvss3_nvd_c vulnerability_cvss3_nvd_i vulnerability_cvss3_nvd_a vulnerability_cvss2_nvd_av vulnerability_cvss2_nvd_ac vulnerability_cvss2_nvd_au vulnerability_cvss2_nvd_ci vulnerability_cvss2_nvd_ii vulnerability_cvss2_nvd_ai source_cve_cna vulnerability_cvss2_nvd_basescore vulnerability_cvss3_nvd_basescore
