CVE-2021-23840Patch(debian / business_intelligence)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch debian business_intelligence systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • business_intelligence
  • communications_cloud_native_core_policy
  • debian_linux
  • enterprise_manager_for_storage_management

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
business_intelligencecommunications_cloud_native_core_policydebian_linuxenterprise_manager_for_storage_managemententerprise_manager_ops_centerepolicy_orchestratorgraalvmjd_edwards_enterpriseone_toolsjd_edwards_world_securitylog_correlation_engine

20 versions affected across 27 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-24: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-24: 104-24
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH SEVERITY: CVE-2021-23840 (CVSS 7.5) OpenSSL integer overflow in EVP_CipherUpdate/EVP_EncryptUpdate/EVP_DecryptUpdate functions. Affects versions 1.1.1-1.1.1i & 1.0.2x. Upgrade to 1.1.1j immediately. #CVE #Vulnerability #PatchNow https://t.co/MnfFWimWfk

    Post summary

    The tweet announces CVE‑2021‑23840, provides technical details, and urges upgrading to OpenSSL 1.1.1j to mitigate the integer overflow vulnerability.

    0000040
    26 followersView on X
CPE platform detail49 entries

49 of 49 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux10.0--
HWfujitsum10-1---
OSfujitsum10-1_firmware---
HWfujitsum10-4---
OSfujitsum10-4_firmware---
HWfujitsum10-4s---
OSfujitsum10-4s_firmware---
HWfujitsum12-1---
OSfujitsum12-1_firmware---
HWfujitsum12-2---
OSfujitsum12-2_firmware---
HWfujitsum12-2s---
OSfujitsum12-2s_firmware---
Appmcafeeepolicy_orchestrator---
Appmcafeeepolicy_orchestrator5.10.0--
Appmcafeeepolicy_orchestrator5.10.0--
Appmcafeeepolicy_orchestrator5.10.0--
Appmcafeeepolicy_orchestrator5.10.0--
Appmcafeeepolicy_orchestrator5.10.0--
Appmcafeeepolicy_orchestrator5.10.0--
Appmcafeeepolicy_orchestrator5.10.0--
Appmcafeeepolicy_orchestrator5.10.0--
Appmcafeeepolicy_orchestrator5.10.0--
Appmcafeeepolicy_orchestrator5.10.0--
Appmcafeeepolicy_orchestrator5.10.0--
Appnodejsnode.js---
Appnodejsnode.js---
Appnodejsnode.js14.15.0--
Appopensslopenssl---
Apporaclebusiness_intelligence12.2.1.3.0--
Apporaclebusiness_intelligence12.2.1.4.0--
Apporaclebusiness_intelligence5.5.0.0.0--
Apporaclebusiness_intelligence5.9.0.0.0--
Apporaclecommunications_cloud_native_core_policy1.15.0--
Apporacleenterprise_manager_for_storage_management13.4.0.0--
Apporacleenterprise_manager_ops_center12.4.0.0--
Apporaclegraalvm19.3.5--
Apporaclegraalvm20.3.1.2--
Apporaclegraalvm21.0.0.2--
Apporaclejd_edwards_enterpriseone_tools---
Apporaclejd_edwards_world_securitya9.4--
Apporaclemysql_server---
Apporaclenosql_database---
Apptenablelog_correlation_engine---
Apptenablenessus_network_monitor5.11.0--
Apptenablenessus_network_monitor5.11.1--
Apptenablenessus_network_monitor5.12.0--
Apptenablenessus_network_monitor5.12.1--
Apptenablenessus_network_monitor5.13.0--

Explore more