Deserialization of Untrusted Data in IBM WebSphere Application Server - CVE-2023-23477
Published: January 31, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can send specially crafted data to the server and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
IBM Security Guardium Key Lifecycle Manager (GKLM)
WebSphere Remote Server
IBM Business Automation Workflow
IBM Tivoli Netcool/OMNIbus WebGUI
Jazz for Service Management
IBM Maximo Asset Management
IBM Intelligent Operations Center
IBM Security Identity Manager
Tivoli Composite Application Manager for Application Diagnostics
Business Monitor
IBM Tivoli Network Manager (ITNM)
How to mitigate CVE-2023-23477
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.14
IBM Intelligent Operations Center - update to 5.2.3
External References
Related Security Bulletins
- Remote code execution in IBM WebSphere Application Server
- Deserialization of untrusted data in IBM Maximo Asset Management
- Deserialization of untrusted data in IBM Business Monitor
- Deserialization of untrusted data in IBM Jazz for Service Management
- Deserialization of untrusted data in IBM Security Identity Manager
- Deserialization of untrusted data in IBM Tivoli Netcool/OMNIbus
- Deserialization of untrusted data in IBM Business Automation Workflow
- Deserialization of untrusted data in IBM WebSphere Remote Server
- Deserialization of untrusted data in IBM Tivoli Composite Application Manager for Application Diagnostics
- Deserialization of untrusted data in IBM Security Key Lifecycle Manager
- Multiple vulnerabilities in IBM Intelligent Operations Center (IOC)
- Deserialization of untrusted data in IBM Tivoli Network Manager