Resource exhaustion in Jetty - CVE-2023-26048
Published: April 18, 2023 / Updated: November 28, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing multipart requests in request.getParameter(). A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Debian Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Development Tools Module
openSUSE Leap
openEuler
Cloudera Observability with IBM
Cognos Dashboards on Cloud Pak for Data
DataStage on Cloud Pak for Data
Rational Synergy
InfoSphere Data Architect
IBM Security Verify Information Queue
Cloud Pak for Network Automation
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Storage Resource Manager
User Entity Behavior Analytics
StreamSets Data Collector
IBM Engineering Systems Design Rhapsody
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling B2B Integrator
IBM Sterling Control Center
IBM Cloud Pak for Data System
Log Analysis
IBM MaaS360 Mobile Enterprise Gateway
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
IBM Sterling Connect:Direct Web Services
IBM Maximo Asset Management
Maximo Manage Application in IBM Maximo Application Suite
IBM MQ
Rational Functional Tester (RFT)
Rational Service Tester
IBM InfoSphere Information Server for Cloud
IBM Business Automation Workflow
OpenShift Developer Tools and Services
Red Hat Camel for Spring Boot
Rational Change
IBM Integrated Analytics System
Sterling Connect:Direct Browser User Interface
SecureTransport
JBoss Enterprise Application Platform
AMQ Streams
JBoss Enterprise Application Platform expansion pack (EAP XP)
IBM Qradar SIEM
Red Hat Single Sign-On
Oracle Communications Cloud Native Core Security Edge Protection Proxy
eap7-jboss-jsp (Red Hat package)
eap7-yasson (Red Hat package)
eap7-wildfly-transaction-client (Red Hat package)
eap7-jboss-server-migration (Red Hat package)
eap7-avro (Red Hat package)
eap7-jboss-marshalling (Red Hat package)
eap7-undertow (Red Hat package)
eap7-jandex (Red Hat package)
eap7-apache-sshd (Red Hat package)
eap7-activemq-artemis (Red Hat package)
jenkins (Red Hat package)
eap7-weld-core (Red Hat package)
eap7-hal-console (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
eap7-jgroups (Red Hat package)
jenkins-2-plugins (Red Hat package)
eap7-hibernate (Red Hat package)
eap7-jbossws-cxf (Red Hat package)
eap7-wildfly (Red Hat package)
jetty-websocket-common
jetty-client
jetty-cdi
jetty-ant
jetty-annotations
jetty-alpn-server
jetty-alpn-client
jetty
jetty-xml
jetty-websocket-servlet
jetty-websocket-server
jetty-continuation
jetty-websocket-client
jetty-websocket-api
jetty-webapp
jetty-util-ajax
jetty-util
jetty-unixsocket
jetty-start
jetty-spring
jetty-servlets
jetty-http2-server
jetty-jmx
jetty-javax-websocket-server-impl
jetty-javax-websocket-client-impl
jetty-javadoc
jetty-jaspi
jetty-jaas
jetty-io
jetty-infinispan
jetty-httpservice
jetty-servlet
jetty-http2-http-client-transport
jetty-http2-hpack
jetty-http2-common
jetty-http2-client
jetty-http-spi
jetty-http
jetty-fcgi-server
jetty-fcgi-client
jetty-deploy
jetty-osgi-boot
jetty-server
jetty-security
jetty-rewrite
jetty-quickstart
jetty-proxy
jetty-project
jetty-plus
jetty-osgi-boot-warurl
jetty-osgi-boot-jsp
jetty-jsp
jetty-osgi-alpn
jetty-nosql
jetty-maven-plugin
jetty-jstl
jetty-jspc-maven-plugin
jetty-jndi
jetty9 (Debian package)
jetty-fcgi
jetty-minimal-javadoc
jetty-openid
eap7-infinispan (Red Hat package)
rh-sso7-keycloak (Red Hat package)
eap7-guava-libraries (Red Hat package)
watsonx.data
IBM MaaS360 VPN Module
Dell EMC Storage Monitoring and Reporting (SMR)
Operational Decision Manager
IBM Cognos Analytics
IBM InfoSphere Information Server
How to mitigate CVE-2023-26048
Cognos Dashboards on Cloud Pak for Data - update to 4.8.0
DataStage on Cloud Pak for Data - update to 5.0.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
Rational Change - update to 5.3.2.6
SecureTransport - update to 5.5-20230525
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.0.8, 6.1.2.4, 6.2.0.0
IBM Sterling Control Center - update to 6.2.1.0.15
Rational Synergy - update to 7.2.2.6
JBoss Enterprise Application Platform - update to 7.4.14
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
Red Hat Single Sign-On - update to 7.6.7
InfoSphere Data Architect - update to 9.2.1
IBM Security Verify Information Queue - update to 10.0.5
eap7-jboss-jsp (Red Hat package) - addressed in versions api_2.3_spec-2.0.1-1.Final_redhat_00001.1.el7eap, api_2.3_spec-2.0.1-1.Final_redhat_00001.1.el8eap, api_2.3_spec-2.0.1-1.Final_redhat_00001.1.el9eap
IBM Cloud Pak for Data System - update to 1.0.8.2
eap7-yasson (Red Hat package) - addressed in versions 1.0.11-4.redhat_00002.1.el7eap, 1.0.11-4.redhat_00002.1.el8eap, 1.0.11-4.redhat_00002.1.el9eap
IBM Integrated Analytics System - update to 1.0.28.1
eap7-wildfly-transaction-client (Red Hat package) - addressed in versions 1.1.16-1.Final_redhat_00001.1.el7eap, 1.1.16-1.Final_redhat_00001.1.el8eap, 1.1.16-1.Final_redhat_00001.1.el9eap
Log Analysis - update to 1.3.8 Fix Pack 1
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-37
eap7-jboss-server-migration (Red Hat package) - addressed in versions 1.10.0-33.Final_redhat_00032.1.el7eap, 1.10.0-33.Final_redhat_00032.1.el8eap, 1.10.0-33.Final_redhat_00032.1.el9eap
eap7-avro (Red Hat package) - addressed in versions 1.11.3-1.redhat_00001.1.el7eap, 1.11.3-1.redhat_00001.1.el8eap, 1.11.3-1.redhat_00001.1.el9eap
watsonx.data - update to 2.0.3
eap7-jboss-marshalling (Red Hat package) - addressed in versions 2.0.14-1.SP1_redhat_00001.1.el7eap, 2.0.14-1.SP1_redhat_00001.1.el8eap, 2.0.14-1.SP1_redhat_00001.1.el9eap
eap7-undertow (Red Hat package) - addressed in versions 2.2.28-1.SP1_redhat_00001.1.el7eap, 2.2.28-1.SP1_redhat_00001.1.el8eap, 2.2.28-1.SP1_redhat_00001.1.el9eap
eap7-jandex (Red Hat package) - addressed in versions 2.4.4-1.Final_redhat_00001.1.el7eap, 2.4.4-1.Final_redhat_00001.1.el8eap, 2.4.4-1.Final_redhat_00001.1.el9eap
AMQ Streams - update to 2.5.0
Cloud Pak for Network Automation - update to 2.7
eap7-apache-sshd (Red Hat package) - addressed in versions 2.9.3-1.redhat_00001.1.el7eap, 2.9.3-1.redhat_00001.1.el8eap, 2.9.3-1.redhat_00001.1.el9eap
eap7-activemq-artemis (Red Hat package) - addressed in versions 2.16.0-17.redhat_00051.1.el7eap, 2.16.0-17.redhat_00051.1.el8eap, 2.16.0-17.redhat_00051.1.el9eap
jenkins (Red Hat package) - update to 2.426.3.1706515686-3.el8
IBM MaaS360 VPN Module - update to 3.000.200
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.200
eap7-weld-core (Red Hat package) - addressed in versions 3.1.10-2.Final_redhat_00001.1.el7eap, 3.1.10-2.Final_redhat_00001.1.el8eap, 3.1.10-2.Final_redhat_00001.1.el9eap
eap7-hal-console (Red Hat package) - addressed in versions 3.3.20-1.Final_redhat_00001.1.el7eap, 3.3.20-1.Final_redhat_00001.1.el8eap, 3.3.20-1.Final_redhat_00001.1.el9eap
eap7-jboss-xnio-base (Red Hat package) - addressed in versions 3.8.11-1.SP1_redhat_00001.1.el7eap, 3.8.11-1.SP1_redhat_00001.1.el8eap, 3.8.11-1.SP1_redhat_00001.1.el9eap
Red Hat Camel for Spring Boot - update to 4.0.0
JBoss Enterprise Application Platform expansion pack (EAP XP) - update to 4.0.2.GA
eap7-jgroups (Red Hat package) - addressed in versions 4.2.23-1.Final_redhat_00001.1.el7eap, 4.2.23-1.Final_redhat_00001.1.el8eap, 4.2.23-1.Final_redhat_00001.1.el9eap
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
Storage Resource Manager - update to 4.10.0.3
jenkins-2-plugins (Red Hat package) - update to 4.12.1706515741-1.el8
User Entity Behavior Analytics - update to 5.0.2
eap7-hibernate (Red Hat package) - addressed in versions 5.3.32-1.Final_redhat_00001.1.el7eap, 5.3.32-1.Final_redhat_00001.1.el8eap, 5.3.32-1.Final_redhat_00001.1.el9eap
eap7-jbossws-cxf (Red Hat package) - addressed in versions 5.4.9-1.Final_redhat_00001.1.el7eap, 5.4.9-1.Final_redhat_00001.1.el8eap, 5.4.9-1.Final_redhat_00001.1.el9eap
IBM Sterling Secure Proxy - update to 6.0.3 iFix 08
IBM Sterling External Authentication Server - addressed in versions 6.0.3.0 iFix 08, 6.1.0.0 iFix 04
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.19, 6.2.0.17
StreamSets Data Collector - update to 7.0.0
eap7-wildfly (Red Hat package) - addressed in versions 7.4.14-5.GA_redhat_00002.1.el7eap, 7.4.14-5.GA_redhat_00002.1.el8eap, 7.4.14-5.GA_redhat_00002.1.el9eap
IBM Maximo Asset Management - update to 7.6.1.3.11
Maximo Manage Application in IBM Maximo Application Suite - update to 8.6.4
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
IBM MQ - addressed in versions 9.0.0.19, 9.1.0.17, 9.2.0.15, 9.3.3
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2, 10.0.0.1
jetty-websocket-common - update to 9.4.16-7
jetty-client - update to 9.4.16-7
jetty-cdi - update to 9.4.16-7
jetty-ant - update to 9.4.16-7
jetty-annotations - update to 9.4.16-7
jetty-alpn-server - update to 9.4.16-7
jetty-alpn-client - update to 9.4.16-7
jetty - update to 9.4.16-7
jetty-xml - update to 9.4.16-7
jetty-websocket-servlet - update to 9.4.16-7
jetty-websocket-server - update to 9.4.16-7
jetty-continuation - update to 9.4.16-7
jetty-websocket-client - update to 9.4.16-7
jetty-websocket-api - update to 9.4.16-7
jetty-webapp - update to 9.4.16-7
jetty-util-ajax - update to 9.4.16-7
jetty-util - update to 9.4.16-7
jetty-unixsocket - update to 9.4.16-7
jetty-start - update to 9.4.16-7
jetty-spring - update to 9.4.16-7
jetty-servlets - update to 9.4.16-7
jetty-http2-server - update to 9.4.16-7
jetty-jmx - update to 9.4.16-7
jetty-javax-websocket-server-impl - update to 9.4.16-7
jetty-javax-websocket-client-impl - update to 9.4.16-7
jetty-javadoc - update to 9.4.16-7
jetty-jaspi - update to 9.4.16-7
jetty-jaas - update to 9.4.16-7
jetty-io - update to 9.4.16-7
jetty-infinispan - update to 9.4.16-7
jetty-httpservice - update to 9.4.16-7
jetty-servlet - update to 9.4.16-7
jetty-http2-http-client-transport - update to 9.4.16-7
jetty-http2-hpack - update to 9.4.16-7
jetty-http2-common - update to 9.4.16-7
jetty-http2-client - update to 9.4.16-7
jetty-http-spi - update to 9.4.16-7
jetty-http - update to 9.4.16-7
jetty-fcgi-server - update to 9.4.16-7
jetty-fcgi-client - update to 9.4.16-7
jetty-deploy - update to 9.4.16-7
jetty-osgi-boot - update to 9.4.16-7
jetty-server - update to 9.4.16-7
jetty-security - update to 9.4.16-7
jetty-rewrite - update to 9.4.16-7
jetty-quickstart - update to 9.4.16-7
jetty-proxy - update to 9.4.16-7
jetty-project - update to 9.4.16-7
jetty-plus - update to 9.4.16-7
jetty-osgi-boot-warurl - update to 9.4.16-7
jetty-osgi-boot-jsp - update to 9.4.16-7
jetty-jsp - update to 9.4.16-7
jetty-osgi-alpn - update to 9.4.16-7
jetty-nosql - update to 9.4.16-7
jetty-maven-plugin - update to 9.4.16-7
jetty-jstl - update to 9.4.16-7
jetty-jspc-maven-plugin - update to 9.4.16-7
jetty-jndi - update to 9.4.16-7
jetty9 (Debian package) - addressed in versions 9.4.39-3+deb11u2, 9.4.50-4+deb12u1
jetty-continuation - update to 9.4.51-150200.3.19.2
jetty-xml - update to 9.4.51-150200.3.19.2
jetty-util - update to 9.4.51-150200.3.19.2
jetty-fcgi - update to 9.4.51-150200.3.19.2
jetty-deploy - update to 9.4.51-150200.3.19.2
jetty-server - update to 9.4.51-150200.3.19.2
jetty-io - update to 9.4.51-150200.3.19.2
jetty-util-ajax - update to 9.4.51-150200.3.19.2
jetty-jaas - update to 9.4.51-150200.3.19.2
jetty-minimal-javadoc - update to 9.4.51-150200.3.19.2
jetty-jmx - update to 9.4.51-150200.3.19.2
jetty-ant - update to 9.4.51-150200.3.19.2
jetty-servlet - update to 9.4.51-150200.3.19.2
jetty-quickstart - update to 9.4.51-150200.3.19.2
jetty-servlets - update to 9.4.51-150200.3.19.2
jetty-annotations - update to 9.4.51-150200.3.19.2
jetty-openid - update to 9.4.51-150200.3.19.2
jetty-proxy - update to 9.4.51-150200.3.19.2
jetty-cdi - update to 9.4.51-150200.3.19.2
jetty-jndi - update to 9.4.51-150200.3.19.2
jetty-webapp - update to 9.4.51-150200.3.19.2
jetty-jsp - update to 9.4.51-150200.3.19.2
jetty-plus - update to 9.4.51-150200.3.19.2
jetty-start - update to 9.4.51-150200.3.19.2
jetty-client - update to 9.4.51-150200.3.19.2
jetty-security - update to 9.4.51-150200.3.19.2
jetty-http - update to 9.4.51-150200.3.19.2
jetty-rewrite - update to 9.4.51-150200.3.19.2
jetty-http-spi - update to 9.4.51-150200.3.19.2
Rational Functional Tester (RFT) - update to 10.5.3
Rational Service Tester - update to 10.5.4
eap7-infinispan (Red Hat package) - addressed in versions 11.0.18-1.Final_redhat_00001.1.el7eap, 11.0.18-1.Final_redhat_00001.1.el8eap, 11.0.18-1.Final_redhat_00001.1.el9eap
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM InfoSphere Information Server for Cloud - update to 11.7.1.4 Service pack 1
rh-sso7-keycloak (Red Hat package) - addressed in versions 18.0.12-1.redhat_00001.1.el7sso, 18.0.12-1.redhat_00001.1.el8sso, 18.0.12-1.redhat_00001.1.el9sso
IBM Business Automation Workflow - addressed in versions 21.0.3 IF033, 23.0.2 IF005
eap7-guava-libraries (Red Hat package) - addressed in versions 32.1.1-2.jre_redhat_00001.1.el7eap, 32.1.1-2.jre_redhat_00001.1.el8eap, 32.1.1-2.jre_redhat_00001.1.el9eap
External References
Related Security Bulletins
- Multiple vulnerabilities in Eclipse Jetty
- Multiple vulnerabilities in IBM Security Verify Information Queue
- Multiple vulnerabilities in Axway SecureTransport
- SUSE update for jetty-minimal
- Resource exhaustion in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Rational Functional Tester (RFT)
- Multiple vulnerabilities in IBM Sterling Connect:Direct Web Services
- Resource exhaustion in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Sterling Connect:Direct Browser User Interface
- Multiple vulnerabilities in IBM Rational Synergy
- Multiple vulnerabilities in IBM Rational Change
- Resource exhaustion in IBM Cloud Pak for Data System
- Multiple vulnerabilities in IBM MQ Explorer
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- Multiple vulnerabilities in IBM Sterling External Authentication Server
- Multiple vulnerabilities in Red Hat AMQ Streams
- Debian update for jetty9
- Multiple vulnerabilities in IBM MaaS360 Mobile Enterprise Gateway and VPN Module
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat Integration Camel for Spring Boot 4.0
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Resource exhaustion in IBM Integrated Analytics System
- Resource exhaustion in IBM Maximo Asset Management
- Maximo Manage Application in IBM Maximo Application Suite update for Jetty
- IBM Rational Service Tester update for Eclipse Jetty
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4.14 on RHEL 9
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 7
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- OpenShift Developer Tools and Services for OCP 4.12 update for Jenkins and Jenkins-2-plugins
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 on RHEL 9
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 on RHEL 7
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 on RHEL 8
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Resource exhaustion in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in IBM Business Automation Workflo
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in JBoss Enterprise Application Platform expansion pack (EAP XP) 4.0.2
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- IBM watsonx.data update for FasterXML jackson-databind
- openEuler 20.03 LTS SP4 update for jetty
- openEuler 22.03 LTS SP3 update for jetty
- openEuler 22.03 LTS SP4 update for jetty
- openEuler 24.03 LTS update for jetty
- openEuler 22.03 LTS SP1 update for jetty
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in IBM Watson Knowledge Catalog
- Multiple vulnerabilities in IBM Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in IBM User Entity Behavior Analytics
- Multiple vulnerabilities in IBM StreamSets Data Collector
- Multiple vulnerabilities in IBM InfoSphere Data Architect