Resource exhaustion in jline3 - CVE-2023-50572
Published: December 23, 2024
Vulnerability identifier: #VU101896
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50572
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
jline3
IBM Application Suite - IBM Asset Data Dictionary Component
Cloudera Observability with IBM
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Cloud Object Storage Systems
IBM InfoSphere Information Server
IBM Application Suite - IBM Asset Data Dictionary Component
Cloudera Observability with IBM
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Cloud Object Storage Systems
IBM InfoSphere Information Server
How to mitigate CVE-2023-50572
Install updates from vendor's website.
jline3 - update to 3.26.3
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.13
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
Cloudera Observability with IBM - update to 3.6.2
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.13
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
Cloudera Observability with IBM - update to 3.6.2
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
External References
Related Security Bulletins
- Denial of service in jline3
- Multiple vulnerabilities in IBM Asset Data Dictionary Component
- Multiple vulnerabilities in IBM Watson Knowledge Catalog
- Multiple vulnerabilities in IBM Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in IBM Cloud Object System
- IBM InfoSphere Information Server update for jline-groovy