Uncaught Exception in yaml - CVE-2023-2251

 

Uncaught Exception in yaml - CVE-2023-2251

Published: May 29, 2023


Vulnerability identifier: #VU76605
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2251
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service condition.

The vulnerability exists due uncaught exception in the parseDocument() and parseAllDocuments() functions. A remote unauthenticated attacker can send a specially crafted input and cause a denial of service condition.


Affected software

yaml
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Cloud Pak for Security (CP4S)
Cloud Pak for Data
IBM Cloud Pak for Multicloud Management
IBM Edge Application Manager
IBM Watson Assistant for IBM Cloud Pak for Data
Netcool Operations Insight
IBM Fusion HCI
IBM Decision Optimization for Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Security QRadar Analyst Workflow

How to mitigate CVE-2023-2251

Install updates from vendor's website.

yaml - update to 2.0.0-5
Cloud Pak for Security (CP4S) - update to 1.10.13.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
Netcool Operations Insight - update to 1.6.10
Cloud Pak for Network Automation - update to 2.4.7
IBM Fusion HCI - update to 2.6.1
IBM Security QRadar Analyst Workflow - update to 2.32.0
IBM Cloud Pak for Watson AIOps - update to 3.7.2
IBM Decision Optimization for Cloud Pak for Data - update to 4.7
Cloud Pak for Data - update to 4.8.5
App Connect Enterprise Certified Container - addressed in versions 5.0.7, 8.1.0

External References

Related Security Bulletins