Input validation error in IBM WebSphere Application Server Liberty - CVE-2023-38737
Published: August 17, 2023
Vulnerability identifier: #VU79665
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38737
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request to the server and perform a denial of service (DoS) attack.
Affected software
IBM WebSphere Application Server Liberty
IBM Global High Availability Mailbox
Engineering Workflow Management
IBM SPSS Analytic Server
IBM Maximo Application Suite
IBM Cloud Transformation Advisor
IBM Match 360
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Spectrum Control
IBM Sterling Partner Engagement Manager
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM Sterling Order Management
Storage Protect Client
Engineering Test Management
IBM Engineering Requirements Management DOORS Next
IBM OpenPages with Watson
PowerVM NovaLink
IBM Planning Analytics Workspace
Storage Protect Operations Center
IBM Cognos Controller
Voice Gateway
Planning Analytics Local
IBM Cognos Analytics
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Global High Availability Mailbox
Engineering Workflow Management
IBM SPSS Analytic Server
IBM Maximo Application Suite
IBM Cloud Transformation Advisor
IBM Match 360
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Spectrum Control
IBM Sterling Partner Engagement Manager
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM Sterling Order Management
Storage Protect Client
Engineering Test Management
IBM Engineering Requirements Management DOORS Next
IBM OpenPages with Watson
PowerVM NovaLink
IBM Planning Analytics Workspace
Storage Protect Operations Center
IBM Cognos Controller
Voice Gateway
Planning Analytics Local
IBM Cognos Analytics
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2023-38737
Install updates from vendor's website.
IBM Maximo Application Suite - addressed in versions 8.10.6, 8.11.1
IBM Cognos Controller - update to 11.0.1.0.3
Voice Gateway - addressed in versions 1.0.8.7, 1.0.8.10
PowerVM NovaLink - addressed in versions 2.0.3.1.1-230926_4635, 2.1.1-230921_4631
Planning Analytics Local - update to 2.0.9.19
IBM Planning Analytics Workspace - update to 2.0.91
IBM Cloud Transformation Advisor - update to 3.7.0
IBM Match 360 - update to 4.7.4
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Spectrum Control - update to 5.4.11
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.10, 6.2.0.8, 6.2.3.1
IBM Tivoli Netcool Impact - update to 7.1.0.31
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Operations Center - update to 8.1.21
IBM TXSeries for Multiplatforms - addressed in versions 8.2.0.2, 9.1.0.2
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix22, 11.1.0.0 ifix14
IBM CICS TX Standard - update to 11.1.0.0 ifix14
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4
IBM Cognos Controller - update to 11.0.1.0.3
Voice Gateway - addressed in versions 1.0.8.7, 1.0.8.10
PowerVM NovaLink - addressed in versions 2.0.3.1.1-230926_4635, 2.1.1-230921_4631
Planning Analytics Local - update to 2.0.9.19
IBM Planning Analytics Workspace - update to 2.0.91
IBM Cloud Transformation Advisor - update to 3.7.0
IBM Match 360 - update to 4.7.4
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Spectrum Control - update to 5.4.11
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.10, 6.2.0.8, 6.2.3.1
IBM Tivoli Netcool Impact - update to 7.1.0.31
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Operations Center - update to 8.1.21
IBM TXSeries for Multiplatforms - addressed in versions 8.2.0.2, 9.1.0.2
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix22, 11.1.0.0 ifix14
IBM CICS TX Standard - update to 11.1.0.0 ifix14
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4
External References
Related Security Bulletins
- Denial of service in IBM WebSphere Application Server Liberty
- Input validation error in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Voice Gateway
- Input validation error in IBM PowerVM Novalink
- Input validation error in IBM CICS TX Advanced and IBM CICS TX Standard
- Input validation error in IBM TXSeries for Multiplatforms
- Multiple vulnerabilities in IBM Planning Analytics
- IBM Maximo Application Suite - Monitor Component update for WebSphere Application Server Liberty
- Input validation error in IBM Spectrum Control
- IBM Storage Protect Operations Center update for WebSphere Application Server Liberty
- Multiple vulnerabilities in IBM OpenPages with Watson
- Input validation error in IBM Match 360
- Multiple vulnerabilities in IBM Application Performance Management
- Input validation error in IBM Engineering Lifecycle Engineering
- Multiple vulnerabilities in IBM Storage Protect for Workstations
- Input validation error in IBM Sterling Order Management
- Input validation error in IBM Sterling Partner Engagement Manager
- Multiple vulnerabilities in IBM Cognos Analytics
- Input validation error in IBM Global High Availability Mailbox
- Multiple vulnerabilities in IBM Cognos Controller
- IBM SPSS Analytic Server update for IBM WebSphere Application Server Liberty
- Multiple vulnerabilities in IBM Knowledge Catalog for IBM Cloud Pak for Data