Input validation error in IBM WebSphere Application Server Liberty - CVE-2023-38737

 

Input validation error in IBM WebSphere Application Server Liberty - CVE-2023-38737

Published: August 17, 2023


Vulnerability identifier: #VU79665
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38737
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request to the server and perform a denial of service (DoS) attack.


Affected software

IBM WebSphere Application Server Liberty
IBM Global High Availability Mailbox
Engineering Workflow Management
IBM SPSS Analytic Server
IBM Maximo Application Suite
IBM Cloud Transformation Advisor
IBM Match 360
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Spectrum Control
IBM Sterling Partner Engagement Manager
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM Sterling Order Management
Storage Protect Client
Engineering Test Management
IBM Engineering Requirements Management DOORS Next
IBM OpenPages with Watson
PowerVM NovaLink
IBM Planning Analytics Workspace
Storage Protect Operations Center
IBM Cognos Controller
Voice Gateway
Planning Analytics Local
IBM Cognos Analytics
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2023-38737

Install updates from vendor's website.

IBM Maximo Application Suite - addressed in versions 8.10.6, 8.11.1
IBM Cognos Controller - update to 11.0.1.0.3
Voice Gateway - addressed in versions 1.0.8.7, 1.0.8.10
PowerVM NovaLink - addressed in versions 2.0.3.1.1-230926_4635, 2.1.1-230921_4631
Planning Analytics Local - update to 2.0.9.19
IBM Planning Analytics Workspace - update to 2.0.91
IBM Cloud Transformation Advisor - update to 3.7.0
IBM Match 360 - update to 4.7.4
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Spectrum Control - update to 5.4.11
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.10, 6.2.0.8, 6.2.3.1
IBM Tivoli Netcool Impact - update to 7.1.0.31
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Operations Center - update to 8.1.21
IBM TXSeries for Multiplatforms - addressed in versions 8.2.0.2, 9.1.0.2
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix22, 11.1.0.0 ifix14
IBM CICS TX Standard - update to 11.1.0.0 ifix14
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4

External References

Related Security Bulletins