Information disclosure in IBM Java SDK - CVE-2023-30441
Published: April 26, 2023
Vulnerability identifier: #VU75508
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-30441
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
IBM Java SDK
Rational Business Developer (RBD)
IBM InfoSphere Information Server
IBM DB2
Host On-Demand
InfoSphere Data Replication
Rational Synergy
Tivoli System Automation for Multiplatforms
InfoSphere Global Name Management
Storage Protect Server
WebSphere Service Registry and Repository Studio
IBM Virtualization Engine TS7700 3948-VED
IBM MQ Appliance
IBM VIOS
IBM AIX
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
IBM i
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Legacy Module
openSUSE Leap
WebSphere Service Registry and Repository
IBM Business Automation Workflow
z/Transaction Processing Facility ( z/TPF)
IBM Intelligent Operations Center
IBM Rational Build Forge
Netcool/OMNIbus
IBM Common Licensing
IBM Operations Analytics Predictive Insights
IBM Tivoli System Automation Application Manager
IBM Sterling Connect:Direct Web Services
IBM Tivoli Business Service Manager
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
IBM MQ
IBM Cloud Pak for Business Automation
SPSS Statistics
IBM Data Risk Manager
IBM Tivoli Application Dependency Discovery Manager
Sterling Connect:Direct Browser User Interface
IBM Cloud Pak for Multicloud Management
IBM Data Studio Client
IBM Tivoli Network Manager (ITNM)
DB2 Recovery Expert for LUW
IBM Copy Services Manager
IBM Qradar SIEM
java-1_8_0-ibm
java-1_8_0-ibm-alsa
java-1_8_0-ibm-plugin
java-1_8_0-ibm-devel
java-1_8_0-ibm-demo
java-1_8_0-ibm-src
java-1_8_0-ibm-32bit
java-1_8_0-ibm-devel-32bit
IBM Cloud Pak System
IBM Spectrum Virtualize
Virtualization Engine TS7700 3957-VEC
Rational Business Developer (RBD)
IBM InfoSphere Information Server
IBM DB2
Host On-Demand
InfoSphere Data Replication
Rational Synergy
Tivoli System Automation for Multiplatforms
InfoSphere Global Name Management
Storage Protect Server
WebSphere Service Registry and Repository Studio
IBM Virtualization Engine TS7700 3948-VED
IBM MQ Appliance
IBM VIOS
IBM AIX
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
IBM i
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Legacy Module
openSUSE Leap
WebSphere Service Registry and Repository
IBM Business Automation Workflow
z/Transaction Processing Facility ( z/TPF)
IBM Intelligent Operations Center
IBM Rational Build Forge
Netcool/OMNIbus
IBM Common Licensing
IBM Operations Analytics Predictive Insights
IBM Tivoli System Automation Application Manager
IBM Sterling Connect:Direct Web Services
IBM Tivoli Business Service Manager
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
IBM MQ
IBM Cloud Pak for Business Automation
SPSS Statistics
IBM Data Risk Manager
IBM Tivoli Application Dependency Discovery Manager
Sterling Connect:Direct Browser User Interface
IBM Cloud Pak for Multicloud Management
IBM Data Studio Client
IBM Tivoli Network Manager (ITNM)
DB2 Recovery Expert for LUW
IBM Copy Services Manager
IBM Qradar SIEM
java-1_8_0-ibm
java-1_8_0-ibm-alsa
java-1_8_0-ibm-plugin
java-1_8_0-ibm-devel
java-1_8_0-ibm-demo
java-1_8_0-ibm-src
java-1_8_0-ibm-32bit
java-1_8_0-ibm-devel-32bit
IBM Cloud Pak System
IBM Spectrum Virtualize
Virtualization Engine TS7700 3957-VEC
How to mitigate CVE-2023-30441
Install updates from vendor's website.
IBM Java SDK - update to 8.0-7.15
IBM Business Automation Workflow - addressed in versions 21.0.3 IF020, 22.0.2 IF004
IBM Data Risk Manager - update to 2.0.6.17
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Data Studio Client - update to 4.2.0
IBM Intelligent Operations Center - update to 5.2.4
Rational Synergy - update to 7.2.2.6
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
IBM Rational Build Forge - update to 8.0.0.24
Netcool/OMNIbus - update to 8.1.0.30
IBM Operations Analytics Predictive Insights - update to 1.3.6.6
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-35
java-1_8_0-ibm - addressed in versions 1.8.0_sr8.5-30.108.1, 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr8.5-30.108.1, 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr8.5-30.108.1, 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr8.5-30.108.1, 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-demo - update to 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-src - update to 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-32bit - update to 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-devel-32bit - update to 1.8.0_sr8.5-150000.3.74.1
IBM Cloud Pak System - update to 2.3.3.6
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.2.0.13, 4.1.0.3.0.9, 4.1.0.4.0.6, 4.1.0.5.0.4
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.4.0.17, 4.1.0.5.0.11, 4.1.0.6.0.6, 4.1.0.7.0.4
DB2 Recovery Expert for LUW - update to 5.5.0.1 IF5
IBM Sterling Connect:Direct Web Services - addressed in versions 6.0.0.14, 6.1.0.18, 6.2.0.15
InfoSphere Global Name Management - addressed in versions 6.0.0.15, 7.0.0.6
IBM Tivoli Business Service Manager - update to 6.2.0.5
IBM Copy Services Manager - update to 6.3.5
IBM Tivoli Netcool Impact - update to 7.1.0.28
IBM Cloud Application Performance Management (APM) - addressed in versions 8.1.4.0.12, 8.1.4.0.14
Storage Protect Server - update to 8.1.19
IBM Spectrum Virtualize - addressed in versions 8.2.1.17, 8.3.1.9, 8.4.0.10, 8.5.0.7, 8.5.2.3, 8.5.4.0
WebSphere Service Registry and Repository Studio - update to 8.5.6.3 IJ46307
Virtualization Engine TS7700 3957-VEC - addressed in versions 8.51.2.12 VTD_EXEC.269, 8.52.102.13 VTD_EXEC.269, 8.52.103.23 VTD_EXEC.269, 8.53.0.63 VTD_EXEC.269, 8.53.1.21 VTD_EXEC.269
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.53.0.63 + VTD_EXEC.269, 8.53.1.21 VTD_EXEC.269
IBM MQ - addressed in versions 9.0.0.14, 9.0.0.17, 9.1.0.12, 9.2.0.7, 9.3.0.2, 9.3.1
IBM MQ Appliance - addressed in versions 9.2.0.7, 9.2.5.3, 9.3.0.1
IBM DB2 - addressed in versions 11.1.4.7, 11.5.7, 11.5.8
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.21, 22.0.2.5
SPSS Statistics - addressed in versions 27.0.1.0, 28.0.1.1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF020, 22.0.2 IF004
IBM Data Risk Manager - update to 2.0.6.17
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Data Studio Client - update to 4.2.0
IBM Intelligent Operations Center - update to 5.2.4
Rational Synergy - update to 7.2.2.6
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
IBM Rational Build Forge - update to 8.0.0.24
Netcool/OMNIbus - update to 8.1.0.30
IBM Operations Analytics Predictive Insights - update to 1.3.6.6
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-35
java-1_8_0-ibm - addressed in versions 1.8.0_sr8.5-30.108.1, 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr8.5-30.108.1, 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr8.5-30.108.1, 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr8.5-30.108.1, 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-demo - update to 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-src - update to 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-32bit - update to 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-devel-32bit - update to 1.8.0_sr8.5-150000.3.74.1
IBM Cloud Pak System - update to 2.3.3.6
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.2.0.13, 4.1.0.3.0.9, 4.1.0.4.0.6, 4.1.0.5.0.4
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.4.0.17, 4.1.0.5.0.11, 4.1.0.6.0.6, 4.1.0.7.0.4
DB2 Recovery Expert for LUW - update to 5.5.0.1 IF5
IBM Sterling Connect:Direct Web Services - addressed in versions 6.0.0.14, 6.1.0.18, 6.2.0.15
InfoSphere Global Name Management - addressed in versions 6.0.0.15, 7.0.0.6
IBM Tivoli Business Service Manager - update to 6.2.0.5
IBM Copy Services Manager - update to 6.3.5
IBM Tivoli Netcool Impact - update to 7.1.0.28
IBM Cloud Application Performance Management (APM) - addressed in versions 8.1.4.0.12, 8.1.4.0.14
Storage Protect Server - update to 8.1.19
IBM Spectrum Virtualize - addressed in versions 8.2.1.17, 8.3.1.9, 8.4.0.10, 8.5.0.7, 8.5.2.3, 8.5.4.0
WebSphere Service Registry and Repository Studio - update to 8.5.6.3 IJ46307
Virtualization Engine TS7700 3957-VEC - addressed in versions 8.51.2.12 VTD_EXEC.269, 8.52.102.13 VTD_EXEC.269, 8.52.103.23 VTD_EXEC.269, 8.53.0.63 VTD_EXEC.269, 8.53.1.21 VTD_EXEC.269
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.53.0.63 + VTD_EXEC.269, 8.53.1.21 VTD_EXEC.269
IBM MQ - addressed in versions 9.0.0.14, 9.0.0.17, 9.1.0.12, 9.2.0.7, 9.3.0.2, 9.3.1
IBM MQ Appliance - addressed in versions 9.2.0.7, 9.2.5.3, 9.3.0.1
IBM DB2 - addressed in versions 11.1.4.7, 11.5.7, 11.5.8
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.21, 22.0.2.5
SPSS Statistics - addressed in versions 27.0.1.0, 28.0.1.1
External References
Related Security Bulletins
- Information disclosure in IBM SDK, Java Technology Edition
- Information disclosure in IBM z/Transaction Processing Facility
- Information disclosure in IBM InfoSphere Information Server
- Information disclosure in IBM Tivoli System Automation Application Manager
- Information disclosure in IBM Java SDK affect IBM Tivoli System Automation for Multiplatforms
- Multiple vulnerabilities in IBM Integration Designer
- Information disclosure in IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products
- Information disclosure in IBM Business Automation Workflow
- Information disclosure in Tivoli Netcool/OMNIbus
- Information disclosure in IBM WebSphere Service Registry and Repository
- Multiple vulnerabilities in IBM AIX
- Information disclosure in IBM Tivoli Netcool Impact
- Information disclosure in IBM Tivoli Business Service Manager
- Information disclosure in IBM MQ Appliance
- Information disclosure in IBM i
- Information disclosure in IBM Operations Analytics Predictive Insights
- Information disclosure in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager
- Information disclosure in IBM Sterling Connect:Direct Browser User Interface
- Information disclosure in IBM MQ
- Information disclosure in IBM Sterling Connect:Direct Web Services
- Information disclosure in IBM Rational Business Developer
- IBM Tivoli Network Manager IP Edition update for Java
- Multiple vulnerabilities in IBM Data Risk Manager
- Information disclosure in IBM Virtualization Engine TS7700
- Information disclosure in IBM Copy Services Manager
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- SUSE update for java-1_8_0-ibm
- SUSE update for java-1_8_0-ibm
- Information disclosure in IBM Storage Protect Server
- Information disclosure in IBM Host On-Demand
- Multiple vulnerabilities in IBM Rational Synergy
- Information disclosure in IBM InfoSphere Global Name Management
- Information disclosure in IBM Intelligent Operations Center
- Information disclosure in DB2 Recovery Expert for Linux, Unix and Windows
- Multiple vulnerabilities in IBM Application Performance Management products
- Multiple vulnerabilities in IBM QRadar SIEM
- Information disclosure in IBM InfoSphere Data Replication
- Multiple vulnerabilities in IBM Rational Build Forge
- Information disclosure in IBM Db2
- Multiple vulnerabilities in IBM Common Licensing
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Information disclosure in SPSS Statistics
- Information disclosure in IBM Data Studio client