Information disclosure in Apache Tomcat - CVE-2023-34981

 

Information disclosure in Apache Tomcat - CVE-2023-34981

Published: June 22, 2023


Vulnerability identifier: #VU77622
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34981
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to HTTP headers are not set in a response. A remote attacker can send a specially crafted HTTP request and gain unauthorized access to sensitive information on the system.


Affected software

Apache Tomcat
IBM i Modernization Engine for Lifecycle Integration
Dell Policy Manager for Secure Connect Gateway (SCG)
Oracle Retail Xstore Point of Service
DataPower Operations Dashboard
Storage Copy Data Management
UrbanCode Build
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
IBM Data Risk Manager
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Oracle Financial Services Model Management and Governance
Oracle Communications Diameter Signaling Router
Oracle SD-WAN Edge
Management Cloud Engine
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
IBM Process Mining
IBM UrbanCode Release
Communications Unified Assurance
Oracle Communications Instant Messaging Server
IBM App Connect Professional
Oracle Agile PLM Framework
Oracle Solaris
Tomcat
watsonx.data
IBM Security SOAR

How to mitigate CVE-2023-34981

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.89, 9.0.75, 10.1.9, 11.0.0-M6
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.5
Cloud Pak for Security (CP4S) - update to 1.10.15.0
IBM Data Risk Manager - update to 2.0.6.18
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Communications Unified Assurance - update to 6.0.3
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.18.00.00
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
Tomcat - update to D.9.0.87.01
DataPower Operations Dashboard - update to 1.0.20.0
Netcool Operations Insight - update to 1.6.11
IBM Process Mining - update to 1.14.2
watsonx.data - update to 2.0.2
Storage Copy Data Management - update to 2.2.23.0
UrbanCode Build - update to 6.1.7.10
IBM UrbanCode Release - update to 6.2.5.11
IBM Security SOAR - update to 50.0

External References

Related Security Bulletins