Deserialization of Untrusted Data in Apache MINA - CVE-2024-52046

 

Deserialization of Untrusted Data in Apache MINA - CVE-2024-52046

Published: December 28, 2024


Vulnerability identifier: #VU101974
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52046
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data in ObjectSerializationDecoder. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Apache MINA
Red Hat Camel for Spring Boot
Storage Defender Copy Data Management
DB2 Data Management Console
DB2 Data Management Console on CPD
Oracle Healthcare Master Person Index
Oracle Business Intelligence Enterprise Edition
Storage Copy Data Management
Oracle Health Sciences Information Manager
Communications Unified Assurance
IBM Sterling B2B Integrator
Oracle Communications Network Integrity
My webMethods Server
Oracle Middleware Common Libraries and Tools
Enterprise Manager Base Platform
Management Cloud Engine
Datastax Enterprise with IBM
IBM Sterling File Gateway
OSS Support Tools
JD Edwards EnterpriseOne Tools
Oracle Managed File Transfer
Oracle Business Process Management Suite
Oracle Access Manager
openEuler
apache-mina-javadoc
apache-mina-mina-core
apache-mina-mina-filter-compression
apache-mina-mina-http
apache-mina-mina-statemachine
apache-mina
Operational Decision Manager

How to mitigate CVE-2024-52046

Install updates from vendor's website.

Apache MINA - addressed in versions 2.0.27, 2.1.10, 2.2.4
Storage Defender Copy Data Management - update to 2.3.1.0
DB2 Data Management Console - update to 3.1.13.1
DB2 Data Management Console on CPD - update to 5.1.2
IBM Sterling B2B Integrator - addressed in versions 6.2.0.6.1, 6.2.1.2, 6.2.2.1
IBM Sterling File Gateway - addressed in versions 6.2.0.6.1, 6.2.1.2, 6.2.2.1
My webMethods Server - update to 11.1 Fix 1
apache-mina-javadoc - addressed in versions 2.1.10-1, 2.1.11-1
apache-mina-mina-core - addressed in versions 2.1.10-1, 2.1.11-1
apache-mina-mina-filter-compression - addressed in versions 2.1.10-1, 2.1.11-1
apache-mina-mina-http - addressed in versions 2.1.10-1, 2.1.11-1
apache-mina-mina-statemachine - addressed in versions 2.1.10-1, 2.1.11-1
apache-mina - addressed in versions 2.1.10-1, 2.1.11-1
Storage Copy Data Management - update to 2.2.26.0
Red Hat Camel for Spring Boot - update to 4.8.3
Datastax Enterprise with IBM - update to 6.9.22
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 42, 8.11.1.0 Interim fix 39, 8.12.0.1 Interim fix 24, 9.0.0.1 Interim fix 7

External References

Related Security Bulletins