Resource exhaustion in Apache Kafka - CVE-2022-34917

 

Resource exhaustion in Apache Kafka - CVE-2022-34917

Published: September 20, 2022


Vulnerability identifier: #VU67489
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-34917
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote non-authenticated attacker with ability to establish a network connection with the Apache Kafka broker can consume all available memory resources on the system and perform a denial of service (DoS) attack.


Affected software

Apache Kafka
IBM Maximo Application Suite
IBM Operations Analytics Predictive Insights
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management Security Services
IBM Spectrum Control
IBM Sterling B2B Integrator
IBM Maximo Asset Management
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library
watsonx.data
IBM Data Risk Manager
IBM Security Verify Information Queue
Telco Service Orchestrator
webMethods BPM
IBM Security Guardium
IBM InfoSphere Information Server
Oracle Communications BRM - Elastic Charging Engine
Primavera Unifier
IBM Disconnected Log Collector
openEuler
AMQ Streams
kafka
IBM Qradar SIEM

How to mitigate CVE-2022-34917

Install updates from vendor's website.

Apache Kafka - addressed in versions 2.8.2, 3.0.2, 3.1.2, 3.2.3
IBM Operations Analytics Predictive Insights - update to 1.3.6.6
watsonx.data - update to 2.1
IBM Data Risk Manager - update to 2.0.6.15
IBM Security Verify Information Queue - update to 10.0.5
IBM InfoSphere Information Server - update to 11.7.1.4
Netcool Operations Insight - update to 1.6.7
IBM Disconnected Log Collector - update to 1.8.3
AMQ Streams - update to 2.2.0
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
kafka - update to 2.8.2-1
Telco Service Orchestrator - update to 4.2.4
IBM Spectrum Control - update to 5.4.10.1
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
IBM Maximo Asset Management - update to 7.6.1.3.11
webMethods BPM - update to 11.1 Fix 9
IBM Business Automation Workflow - addressed in versions 19.0.0.3, 20.0.0.2, 21.0.3 IF014, 22.0.1, 22.0.1 IF004
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.15, 22.0.1.5
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library - update to 36.0

External References

Related Security Bulletins