Server-Side Request Forgery (SSRF) in request - CVE-2023-28155

 

Server-Side Request Forgery (SSRF) in request - CVE-2023-28155

Published: May 30, 2023


Vulnerability identifier: #VU76617
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2023-28155
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

request
Astronomer with IBM
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Storage Defender – Data Protect
DB2 on Cloud Pak for Data
IBM Maximo Application Suite - AI Broker
IBM Watson Assistant for IBM Cloud Pak for Data
Netcool Operations Insight
IBM Cloud Transformation Advisor
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Spectrum Protect Plus
PowerProtect Data Manager
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Cloud Pak for Security (CP4S)
IBM QRadar Data Synchronization App
Event Streams
IBM Edge Application Manager
IBM Cloud Pak System
IBM App Connect Enterprise

How to mitigate CVE-2023-28155

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Astronomer with IBM - update to 1.0.1
IBM Maximo Application Suite - AI Broker - update to 1.0.1
Cloud Pak for Security (CP4S) - update to 1.10.15.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.1
Netcool Operations Insight - update to 1.6.9
Storage Defender – Data Protect - update to 2.0
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
IBM QRadar Data Synchronization App - update to 3.2.1
IBM Cloud Transformation Advisor - update to 3.5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.7
IBM Decision Optimization for Cloud Pak for Data - update to 4.7.1
DB2 on Cloud Pak for Data - update to 4.8.4
App Connect Enterprise Certified Container - addressed in versions 5.0.9, 9.1.0
IBM Spectrum Protect Plus - update to 10.1.15
IBM App Connect Enterprise - addressed in versions 11.0.0.21, 12.0.9.0
Event Streams - update to 11.2.2
PowerProtect Data Manager - update to 19.19.0-15
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-8

External References

Related Security Bulletins