Resource management error in Spring Boot - CVE-2023-20883

 

Resource management error in Spring Boot - CVE-2023-20883

Published: May 23, 2023


Vulnerability identifier: #VU76427
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20883
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.

Specifically, an application is vulnerable if all of the conditions are true:

  • The application has Spring MVC auto-configuration enabled. This is the case by default if Spring MVC is on the classpath.
  • The application makes use of Spring Boot's welcome page support, either static or templated.
  • Your application is deployed behind a proxy which caches 404 responses.


Affected software

Spring Boot
Red Hat Camel for Spring Boot
IBM Observability with Instana
Oracle SD-WAN Edge
Oracle Banking APIs
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Network Analytics Data Director
IBM Process Mining
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Sterling Control Center
IBM Maximo Application Suite
Red Hat Build of OptaPlanner for Quarkus
IBM InfoSphere Information Server for Cloud
Cloud Pak for Security (CP4S)
Dell Policy Manager for Secure Connect Gateway (SCG)
IBM Business Automation Manager Open Editions
Oracle FLEXCUBE Universal Banking
IBM i Modernization Engine for Lifecycle Integration
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Dell Data Protection Central
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Communications Service Catalog and Design
Oracle Banking Payments
Oracle Banking Supply Chain Finance
Oracle Banking Trade Finance Process Management
Oracle Banking Credit Facilities Process Management
Oracle Banking Liquidity Management
Oracle Banking Origination
Oracle Banking Electronic Data Exchange for Corporates
Oracle Banking Cash Management
Oracle Banking Branch
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Unified Data Repository
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Cloud Foundry UAA
OpenView Performance Manager (OVPM)
Library Support for Spring
Fuse
Dell EMC VxRail Appliance
Operational Decision Manager
IBM InfoSphere Information Server

How to mitigate CVE-2023-20883

Install updates from vendor's website.

Spring Boot - addressed in versions 2.5.15, 2.6.15, 2.7.12, 3.0.7
Cloud Pak for Security (CP4S) - update to 1.10.13.0
Red Hat Camel for Spring Boot - addressed in versions 3.18.3 Patch 2, 3.20.1 Patch 1
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.18.00.00
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.4
IBM Business Automation Manager Open Editions - update to 8.0.4
Oracle Banking Payments - update to 14.3.0
Cloud Foundry UAA - update to 76.13.0
OpenView Performance Manager (OVPM) - update to T0684V01^ABL
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.4
IBM Process Mining - update to 1.14.1
Cloud Pak for Network Automation - update to 2.6.0
Library Support for Spring - update to 2.7.29
IBM Cloud Pak for Watson AIOps - update to 4.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.7
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.4
IBM Sterling Control Center - update to 6.3.0.0.4
Fuse - update to 7.12.0
Dell EMC VxRail Appliance - update to 8.0.311
IBM Maximo Application Suite - addressed in versions 8.9.6, 8.10.4
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 38, 8.11.0.1 Interim fix 20, 8.11.1 Interim fix 8
Red Hat Build of OptaPlanner for Quarkus - update to 8.38.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM InfoSphere Information Server for Cloud - update to 11.7.1.4 Service pack 1
Dell Data Protection Central - update to 19.10.0-4

External References

Related Security Bulletins