Resource exhaustion in jose - CVE-2022-36083
Published: November 25, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the way application handles untrusted JWE tokens A remote attacker can trigger pass the PBKDF2-based JWE key with an extremely high PBES2 Count value and consume significant amount of CPU time, resulting in a denial of service conditions.
Affected software
Cloud Pak for Security (CP4S)
Event Streams
IBM Cloud Pak for Watson AIOps
App Connect Enterprise Certified Container
Netcool Operations Insight
How to mitigate CVE-2022-36083
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Cloud Pak for Watson AIOps - update to 3.5.1
Event Streams - update to 11.0.4
Netcool Operations Insight - update to 1.6.10
External References
Related Security Bulletins
- Denial of service in JOSE
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Denial of service in App Connect Enterprise Certified Container
- Denial of service in IBM Event Streams
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Netcool Operations Insight