Resource exhaustion in Apache Struts - CVE-2023-41835
Published: September 13, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly handles multipart requests. A remote attacker can send a specially crafted multipart request with fields that exceed the maxStringLength limit and force the application to use disk excessively even if the request was denied.
Affected software
Confluence Data Center
Crowd Data Center
IBM Tivoli Netcool/OMNIbus WebGUI
Confluence Server
Crowd Server
IBM Sterling File Gateway
IBM Tivoli Application Dependency Discovery Manager
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
IBM Security Guardium
IBM Sterling Order Management
How to mitigate CVE-2023-41835
Confluence Data Center - addressed in versions 7.19.18, 8.5.5, 8.7.2, 8.8.0
Confluence Server - addressed in versions 7.19.18, 8.5.5, 8.7.2, 8.8.0
Crowd Data Center - update to 5.3.0
Crowd Server - update to 5.3.0
IBM Sterling File Gateway - addressed in versions 6.1.2.6, 6.2.0.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF03
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF03
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.33
IBM Sterling Order Management - update to 10.0.2309.0
External References
Related Security Bulletins
- Denial of service in Apache Struts
- Resource exhaustion in IBM Sterling Order Management
- IBM Tivoli Netcool/OMNIbus WebGUI update for Apache Struts
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager
- Crowd Data Center and Server update for struts2-core
- Confluence Data Center and Server update for struts2-core
- IBM B2B File Gateway update for Apache Struts