Resource exhaustion in Apache Struts - CVE-2023-34149

 

Resource exhaustion in Apache Struts - CVE-2023-34149

Published: June 13, 2023


Vulnerability identifier: #VU77228
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34149
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when processing lists via the getProperty() method. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Apache Struts
IBM Tivoli Application Dependency Discovery Manager
IBM Qradar SIEM
IBM Security Guardium
eDiscovery Manager
IBM Sterling Order Management
Content Collector for Email
Content Collector for File Systems
Content Collector for Microsoft SharePoint
IBM Tivoli Netcool/OMNIbus WebGUI
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Sterling File Gateway

How to mitigate CVE-2023-34149

Install updates from vendor's website.

Apache Struts - addressed in versions 2.5.30.1, 6.1.2.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
eDiscovery Manager - update to 2.2.2.3.8
Content Collector for Email - update to 4.0.1.15 IF006
Content Collector for File Systems - update to 4.0.1.15 IF006
Content Collector for Microsoft SharePoint - update to 4.0.1.15 IF006
EMC ViPR SRM - update to 4.10.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
IBM Sterling File Gateway - addressed in versions 6.0.3.9, 6.1.0.8, 6.1.2.4, 6.2.0.0
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.32
IBM Sterling Order Management - update to 10.0.2309.0

External References

Related Security Bulletins