Resource exhaustion in snappy-java - CVE-2023-34455

 

Resource exhaustion in snappy-java - CVE-2023-34455

Published: June 15, 2023 / Updated: March 21, 2024


Vulnerability identifier: #VU77362
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34455
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

snappy-java
Guardium Data Security Center (GDSC)
Cloudera Observability with IBM
Cognos Dashboards on Cloud Pak for Data
IBM Engineering Requirements Management DOORS Next
IBM Application Suite - IBM Asset Data Dictionary Component
ObjectScale
Cloud Pak for Network Automation
Netezza Performance Server Replication Services
IBM Cloud Pak for Watson AIOps
IBM Business Automation Manager Open Editions
webMethods BPM
InfoSphere Data Replication
IBM Integration Bus
IBM Observability with Instana
IBM Operations Analytics Predictive Insights
Red Hat Integration Camel-K
IBM Spectrum Copy Data Management
Red Hat Integration Camel Extensions for Quarkus
IBM Sterling B2B Integrator
Jira Software Data Center
Log Analysis
Netcool Operations Insight
Red Hat Integration - Service Registry
Red Hat build of Quarkus
QRadar User Behavior Analytics
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite
IBM Spectrum Protect Plus
IBM InfoSphere Information Server for Cloud
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
watsonx.data
IBM Data Risk Manager
IBM Db2 Web Query for i
Red Hat Camel for Spring Boot
IBM App Connect Enterprise
Juniper Secure Analytics (JSA)
Splunk Enterprise
IBM Qradar SIEM
Jira Software Server
Event Streams
IBM Security Guardium
openEuler
snappy-java-javadoc
snappy-java
IBM Disconnected Log Collector
AMQ Streams
AMQ Broker
IBM InfoSphere Information Server

How to mitigate CVE-2023-34455

Install updates from vendor's website.

snappy-java - update to 1.1.10.1
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
Red Hat Integration Camel-K - update to 1.10.5
watsonx.data - update to 2.0.2
IBM Data Risk Manager - update to 2.0.6.18
IBM Spectrum Copy Data Management - update to 2.2.21.0
Red Hat Integration Camel Extensions for Quarkus - update to 2.13.9
Guardium Data Security Center (GDSC) - addressed in versions 3.6.1, 3.8.5
Cloudera Observability with IBM - update to 3.6.2
Red Hat Camel for Spring Boot - addressed in versions 3.18.3 Patch 2, 3.20.2
Cognos Dashboards on Cloud Pak for Data - update to 4.8.0
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.0.8, 6.1.2.4, 6.2.0.0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
Jira Software Data Center - addressed in versions 9.4.16, 9.12.3
Jira Software Server - addressed in versions 9.4.16, 9.12.3
Splunk Enterprise - addressed in versions 9.0.9, 9.1.4, 9.2.1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
snappy-java-javadoc - update to 1.1.2.4-2
snappy-java - update to 1.1.2.4-2
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.8
Log Analysis - update to 1.3.8 Fix Pack 1
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.11
IBM Disconnected Log Collector - update to 1.8.4
AMQ Streams - addressed in versions 2.5.0, 2.5.2
Red Hat Integration - Service Registry - update to 2.5.4
Cloud Pak for Network Automation - update to 2.6.1
Red Hat build of Quarkus - update to 2.13.9
Netezza Performance Server Replication Services - update to 3.0.5.0
IBM Cloud Pak for Watson AIOps - update to 4.1.2
QRadar User Behavior Analytics - update to 4.1.16
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.7.1
App Connect Enterprise Certified Container - addressed in versions 5.0.9, 9.1.0
IBM Maximo Asset Management - addressed in versions 7.6.1.2.36, 7.6.1.3.11
AMQ Broker - update to 7.12.0
IBM Business Automation Manager Open Editions - update to 8.0.6
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Maximo Application Suite - addressed in versions 8.9.6, 8.10.4
IBM Spectrum Protect Plus - update to 10.1.6.4
webMethods BPM - update to 11.1 Fix 9
Event Streams - update to 11.2.3
InfoSphere Data Replication - update to 11.4.0.5.5702
IBM InfoSphere Information Server for Cloud - update to 11.7.1.4 Service pack 1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF024, 23.0.1 IF002
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.24, 23.0.1.2

External References

Related Security Bulletins