Resource exhaustion in Apache Struts - CVE-2023-34396
Published: June 13, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing multipart requests with non-file normal form fields. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Crowd Data Center
Bamboo Server
Content Collector for Email
Content Collector for File Systems
Content Collector for Microsoft SharePoint
IBM Tivoli Netcool/OMNIbus WebGUI
Crowd Server
IBM Tivoli Application Dependency Discovery Manager
IBM Qradar SIEM
MySQL Enterprise Monitor
IBM Security Guardium
Oracle Communications Policy Management
eDiscovery Manager
Storage Virtualize
IBM Sterling Order Management
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
IBM Sterling File Gateway
How to mitigate CVE-2023-34396
Crowd Data Center - update to 5.3.0
Crowd Server - update to 5.3.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
MySQL Enterprise Monitor - update to 8.0.35
Bamboo Server - addressed in versions 9.2.5, 9.3.4
eDiscovery Manager - update to 2.2.2.3.8
Content Collector for Email - update to 4.0.1.15 IF006
Content Collector for File Systems - update to 4.0.1.15 IF006
Content Collector for Microsoft SharePoint - update to 4.0.1.15 IF006
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
EMC ViPR SRM - update to 4.10.0.0
IBM Sterling File Gateway - addressed in versions 6.0.3.9, 6.1.0.8, 6.1.2.4, 6.2.0.0
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.32
Storage Virtualize - addressed in versions 8.4.0.12, 8.5.0.10, 8.6.0.2, 8.6.2.0
IBM Sterling Order Management - update to 10.0.2309.0
External References
Related Security Bulletins
- Multiple DoS vulnerabilities in Apache Struts
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager
- Multiple vulnerabilities in IBM eDiscovery Manager
- Resource exhaustion in Content Collector for Email, Content Collector for File Systems and Content Collector for Microsoft SharePoint.
- Multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus_GUI
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in Oracle Communications Policy Management
- Resource exhaustion in IBM Sterling Order Management
- Resource exhaustion in IBM Security Guardium
- Bamboo Data Center and Server update for Apache Struts
- IBM Storage Virtualize update for Apache Struts
- Multiple vulnerabilities in IBM Sterling File Gateway
- Crowd Data Center and Server update for struts2-core
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)