Information disclosure in AMQ Streams - CVE-2023-0833

 

Information disclosure in AMQ Streams - CVE-2023-0833

Published: March 15, 2023


Vulnerability identifier: #VU73703
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-0833
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the OKHttp component. A remote user can send a specially crafted request to the server containing a header with an illegal value and disclose potentially sensitive information.


Affected software

AMQ Streams
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Spectrum Symphony
IBM Integration Bus
IBM Cloud Pak for Business Automation
IBM Qradar SIEM
IBM Business Automation Manager Open Editions
DataPower Operations Dashboard
User Entity Behavior Analytics
Communications Service Catalog and Design
IBM App Connect Enterprise

How to mitigate CVE-2023-0833

Install updates from vendor's website.

AMQ Streams - addressed in versions 2.2.1, 2.4.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
IBM Spectrum Symphony - update to 7.3.2 FP3
IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF02
IBM Business Automation Manager Open Editions - update to 8.0.7
DataPower Operations Dashboard - update to 1.0.20.1
User Entity Behavior Analytics - update to 5.0.2
IBM Integration Bus - update to 10.1.0.4
IBM App Connect Enterprise - update to 12.0.12.6
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1

External References

Related Security Bulletins