Input validation error in OpenSSL - CVE-2023-4807
Published: September 8, 2023 / Updated: July 3, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the POLY1305 MAC (message authentication code) implementation. A remote attacker can send specially crafted input to the application and corrupt MM registers on Windows 64 platform, resulting in a denial of service condition.
Affected software
MELSOFT MaiLab SW1DND-MAILAB-M
MELSOFT MaiLab SW1DND-MAILABPR-M
Telemetry Dashboard
Liquidware
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
DB2 Query Management Facility
Citrix Workspace App
Webex App VDI
Secured Component Verification (SCV)
IBM Planning Analytics Workspace
Netezza Performance Server Replication Services
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Storage Ceph
IBM Semeru Runtimes
IBM MQ Appliance
Host On-Demand
QRadar Suite
IBM Cloud Pak for Data System
IBM Rational Build Forge
Tenable Nessus
NetWorker
IBM MaaS360 Cloud Extender Agent
IBM MaaS360 Mobile Enterprise Gateway
IBM Cloud Transformation Advisor
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
EasyApache
IBM Spectrum Control
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM Rational ClearCase
IBM Rational ClearQuest
IBM Workload Scheduler
IBM QRadar WinCollect Agent
PowerProtect Data Manager
Juniper Cloud Native Router
IBM Cloud Pak for Multicloud Management
VMware Horizon Client
IBM DataPower Gateway
PeopleSoft Enterprise PeopleTools
Nessus Agent
TeleControl Server Basic
IBM Qradar SIEM
Hyper Historian
IceWall Gen11 certd module for Windows
IBM App Connect Enterprise
Cisco Jabber
Junos OS Evolved
Cisco Webex Meetings
Dell G15 5511
Alienware m15 R6
XPS 8960
Junos cRPD
IBM MaaS360 VPN Module
MobileHMI
ICONICS Suite
GENESIS64
Energy AnalytiX
How to mitigate CVE-2023-4807
MELSOFT MaiLab SW1DND-MAILAB-M - update to 1.06G
MELSOFT MaiLab SW1DND-MAILABPR-M - update to 1.06G
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
QRadar Suite - update to 1.10.18.0
IBM Cloud Pak for Data System - update to 8.10.25.04.SP2
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Rational Build Forge - update to 8.0.0.25
Nessus Agent - update to 10.4.3
Tenable Nessus - addressed in versions 10.5.6, 10.6.2
IBM App Connect Enterprise - addressed in versions 11.0.0.23, 12.0.10.1
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
NetWorker - addressed in versions 19.11.0.6, 19.12.0.2
Junos OS Evolved - addressed in versions 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
Dell G15 5511 - update to 1.26.0
Alienware m15 R6 - update to 1.27.0
Secured Component Verification (SCV) - update to 1.92.0
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
XPS 8960 - update to 2.3.0
Netezza Performance Server Replication Services - update to 3.0.5.1
IBM MaaS360 Cloud Extender Agent - update to 3.000.300.025
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.400
IBM MaaS360 VPN Module - update to 3.000.400
TeleControl Server Basic - update to 3.1.2
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Decision Optimization for Cloud Pak for Data - update to 4.8
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
EasyApache - update to 4 2023-9-20
IBM Spectrum Control - update to 5.4.11
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.24, 6.2.0.23, 6.3.0.7
IBM Sterling Control Center - addressed in versions 6.2.1.0.13, 6.3.1.0.2
Storage Ceph - update to 7.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
IBM Semeru Runtimes - addressed in versions 8.0.392.0, 11.0.21.0, 17.0.9.0
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.17, 8.7.11, 9.0.2
IBM Maximo Application Suite - addressed in versions 8.10.10, 8.11.7
IBM Rational ClearCase - addressed in versions 9.1.0.6, 10.0.1.1
IBM Rational ClearQuest - addressed in versions 9.1.0.6, 10.0.5
IBM MQ Appliance - addressed in versions 9.3.0.15, 9.3.4.1
IBM Workload Scheduler - addressed in versions 9.5.0.7, 10.1.0.4, 10.2.1
IBM DataPower Gateway - addressed in versions 10.0.1.16, 10.5.0.8, 10.5.3
IBM QRadar WinCollect Agent - update to 10.1.9
MobileHMI - update to 10.97.2
ICONICS Suite - update to 10.97.2
GENESIS64 - update to 10.97.2
Energy AnalytiX - update to 10.97.2
Hyper Historian - update to 10.97.2
Host On-Demand - update to 15.0.2
PowerProtect Data Manager - update to 19.19.0-15
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1
External References
Related Security Bulletins
- Denial of service in OpenSSL POLY1305 MAC on Windows
- Multiple vulnerabilities in cPanel EasyApache
- Multiple vulnerabilities in Tenable Nessus
- Multiple vulnerabilities in Tenable Nessus 10.6
- Multiple vulnerabilities in Tenable Nessus Agent
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in IBM Semeru Runtime
- Multiple vulnerabilities in IBM Spectrum Control
- IBM DataPower Gateway update for OpenSSL
- IBM MQ Appliance update for OpenSSL
- HPE IceWall Gen11 certd module for Windows update for OpenSSL
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Dell Platform BIOS update for OpenSSL
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender Agent, Mobile Enterprise Gateway and VPN Module
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms
- Multiple vulnerabilities in IBM CICS Transaction Gateway Desktop Edition
- Input validation error in IBM Rational ClearQuest
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in Siemens Telecontrol Server Basic
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in IBM Planning Analytics Local - IBM Planning Analytics Workspace
- Input validation error in IBM Host On-Demand
- Input validation error in IBM Sterling Connect:Direct Web Service
- Multiple vulnerabilities in IBM Workload Scheduler
- Multiple vulnerabilities in Dell Secured Component Verification (SCV)
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in ICONICS Products
- Junos OS Evolved update for OpenSSL
- Denial of service in Mitsubishi Electric MELSOFT MaiLab
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in IBM Maximo Application Suite - Manage Component
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Db2 Query Management Facility
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Multiple vulnerabilities in IBM Cloud Pak for Data System 2.0
- Dell NetWorker update for OpenSSL
- Multiple vulnerabilities in IBM Netezza Performance Server Replication Services