Resource exhaustion in Cryptacular - CVE-2020-7226
Published: May 12, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within CiphertextHeader.java in Cryptacular. A remote attacker can trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.
Affected software
IBM Data Risk Manager
Oracle WebCenter Sites
IBM Qradar SIEM
Oracle WebLogic Server
How to mitigate CVE-2020-7226
IBM Data Risk Manager - update to 2.0.6.15
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4
External References
- https://github.com/vt-middleware/cryptacular/blob/fafccd07ab1214e3588a35afe3c361519129605f/src/main/java/org/cryptacular/CiphertextHeader.java#L153
- https://github.com/vt-middleware/cryptacular/blob/master/src/main/java/org/cryptacular/CiphertextHeader.java#L153
- https://github.com/vt-middleware/cryptacular/issues/52
- https://lists.apache.org/thread.html/r380781f5b489cb3c818536cd3b3757e806bfe0bca188591e0051ac03@%3Ccommits.ws.apache.org%3E
- https://lists.apache.org/thread.html/rc36b75cabb4d700b48035d15ad8b8c2712bb32123572a1bdaec2510a@%3Cdev.ws.apache.org%3E
- https://lists.apache.org/thread.html/re04e4f8f0d095387fb6b0ff9016a0af8c93f42e1de93b09298bfa547@%3Ccommits.ws.apache.org%3E
- https://lists.apache.org/thread.html/re7f46c4cc29a4616e0aa669c84a0eb34832e83a8eef05189e2e59b44@%3Cdev.ws.apache.org%3E
- https://lists.apache.org/thread.html/rfa4647c58e375996e62a9094bffff6dc350ec311ba955b430e738945@%3Cdev.ws.apache.org%3E
Related Security Bulletins
- Denial of service in Cryptacular
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Oracle WebCenter Sites
- Multiple vulnerabilities in IBM Data Risk Manager