Allocation of Resources Without Limits or Throttling in Apache Tomcat - CVE-2023-28709

 

Allocation of Resources Without Limits or Throttling in Apache Tomcat - CVE-2023-28709

Published: May 22, 2023


Vulnerability identifier: #VU76417
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28709
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an incomplete fox for #VU72427 (CVE-2023-24998). If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed. A remote attacker can initiate a series of uploads and perform a denial of service (DoS) attack.

Affected software

Apache Tomcat
JBoss Web Server
Confluence Server
Amazon Linux AMI
Debian Linux
Gentoo Linux
Oracle Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Oracle Solaris
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Web and Scripting Module
openSUSE Leap
openEuler
IBM Integration Bus
IBM Rational Build Forge
Bamboo Server
IBM UrbanCode Release
UCD - IBM UrbanCode Deploy
Confluence Data Center
IBM Power Hardware Management Console (HMC)
NetWorker
IBM Data Risk Manager
SecureTransport
IBM Qradar SIEM
IBM App Connect Professional
MySQL Enterprise Monitor
Oracle Communications Instant Messaging Server
Oracle Commerce Guided Search
Tomcat
jws5-tomcat-native (Red Hat package)
tomcat-admin-webapps
tomcat-docs-webapp
tomcat-jsp-2_3-api
tomcat
tomcat-webapps
tomcat-el-3_0-api
tomcat-servlet-3_1-api
tomcat-lib
tomcat-javadoc
tomcat8
tomcat-help
tomcat-jsvc
tomcat-servlet-4_0-api
jws5-tomcat (Red Hat package)
tomcat (Red Hat package)
tomcat-servlet-4.0-api
tomcat-jsp-2.3-api
tomcat-el-3.0-api
tomcat9
tomcat-embed
tomcat10 (Debian package)
www-servers/tomcat
Storage Copy Data Management
UrbanCode Build
Index Engines CyberSense
Dell Data Protection Central
IBM Security SOAR

How to mitigate CVE-2023-28709

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.88, 9.0.74, 10.1.8, 11.0.0-M5
IBM Data Risk Manager - update to 2.0.6.18
SecureTransport - update to 5.5-20230629
JBoss Web Server - update to 5.7.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
IBM Rational Build Forge - update to 8.0.0.24
Bamboo Server - addressed in versions 9.2.4, 9.3.1
Tomcat - update to D.9.0.87.01
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.31-15.redhat_15.el7jws, 1.2.31-15.redhat_15.el8jws, 1.2.31-15.redhat_15.el9jws
Storage Copy Data Management - update to 2.2.23.0
UrbanCode Build - update to 6.1.7.10
IBM UrbanCode Release - update to 6.2.5.11
UCD - IBM UrbanCode Deploy - addressed in versions 6.2.7.21, 7.0.5.16, 7.1.2.12, 7.2.3.5, 7.3.2.0
Confluence Data Center - addressed in versions 7.13.19, 7.19.11, 8.4.1
Confluence Server - addressed in versions 7.13.19, 7.19.11, 8.4.1
tomcat-admin-webapps - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-docs-webapp - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.75-150200.41.1
tomcat-jsp-2_3-api - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-webapps - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-el-3_0-api - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-servlet-3_1-api - update to 8.0.53-29.66.1
tomcat-lib - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-javadoc - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.75-150200.41.1
Index Engines CyberSense - update to 8.3
tomcat8 - update to 8.5.89-1.93
tomcat-help - update to 9.0.10-31
tomcat-jsvc - update to 9.0.10-31
tomcat - update to 9.0.10-31
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-15.redhat_00013.1.el7jws, 9.0.62-15.redhat_00013.1.el8jws, 9.0.62-15.redhat_00013.1.el9jws
tomcat (Red Hat package) - addressed in versions 9.0.62-27.el8_9, 9.0.62-37.el9_3
tomcat-servlet-4.0-api - update to 9.0.62-30
tomcat-lib - update to 9.0.62-30
tomcat-jsp-2.3-api - update to 9.0.62-30
tomcat-el-3.0-api - update to 9.0.62-30
tomcat-docs-webapp - update to 9.0.62-30
tomcat-admin-webapps - update to 9.0.62-30
tomcat - update to 9.0.62-30
tomcat-webapps - update to 9.0.62-30
tomcat9 - update to 9.0.71-1
tomcat-embed - update to 9.0.75-150200.41.1
tomcat-jsvc - update to 9.0.75-150200.41.1
tomcat10 (Debian package) - update to 10.1.6-1+deb12u1
www-servers/tomcat - update to 10.1.8
IBM Power Hardware Management Console (HMC) - addressed in versions 10.1.1020.0 SP1, 10.2.1040.0
NetWorker - update to 19.9.0.2
Dell Data Protection Central - update to 19.10.0-4
IBM Security SOAR - update to 49.1

External References

Related Security Bulletins