Resource exhaustion in ActiveMQ Artemis - CVE-2022-23913

 

Resource exhaustion in ActiveMQ Artemis - CVE-2022-23913

Published: February 4, 2022


Vulnerability identifier: #VU60303
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23913
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

ActiveMQ Artemis
B2B Advanced Communications
IBM Business Automation Manager Open Editions
AMQ Broker
JBoss Enterprise Application Platform
Red Hat Process Automation Manager (formerly JBoss BPM Suite)

How to mitigate CVE-2022-23913

Install updates from vendor's website.

ActiveMQ Artemis - addressed in versions 2.19.1, 2.20.0
B2B Advanced Communications - update to 1.0.0.12
AMQ Broker - update to 7.10.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.1
JBoss Enterprise Application Platform - update to 7.4.5
IBM Business Automation Manager Open Editions - update to 8.0.1

External References

Related Security Bulletins