Improper Authorization in Jetty - CVE-2023-41900
Published: September 14, 2023 / Updated: October 12, 2023
Vulnerability details
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to an error in the revocation process. If a Jetty OpenIdAuthenticator uses the optional nested LoginService, and that LoginService decides to revoke an already authenticated user, then the current request will still treat the user as authenticated.
Affected software
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
IBM Operations Analytics Predictive Insights
IBM Sterling B2B Integrator
IBM Sterling Control Center
Rational Service Tester
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
IBM Process Mining
IBM MaaS360 Cloud Extender Agent
IBM MaaS360 Mobile Enterprise Gateway
IBM Sterling Connect:Direct for UNIX
IBM Sterling Secure Proxy
IBM Sterling Connect:Direct Web Services
UCD - IBM UrbanCode Deploy
Rational Functional Tester (RFT)
IBM Content Collector for SAP Applications
Cloud Pak for Network Automation
DataStage on Cloud Pak for Data
Rational Performance Tester
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
User Entity Behavior Analytics
IBM Sterling Connect:Direct for Microsoft Windows
IBM Secure External Authentication Server
Rational Synergy
Storage Protect Server
Rational Change
Sterling Connect:Direct Browser User Interface
Fuse
IBM MaaS360 VPN Module
Operational Decision Manager
IBM Cognos Analytics
jetty9 (Debian package)
jetty-xml
jetty-util
jetty-http
jetty-servlet
jetty-security
jetty-http-spi
jetty-io
jetty-util-ajax
jetty-cdi
jetty-servlets
jetty-rewrite
jetty-plus
jetty-minimal-javadoc
jetty-ant
jetty-openid
jetty-start
jetty-jmx
jetty-fcgi
jetty-webapp
jetty-proxy
jetty-continuation
jetty-jsp
jetty-deploy
jetty-client
jetty-jaas
jetty-server
jetty-jndi
jetty-quickstart
jetty-annotations
IBM Cognos Command Center
How to mitigate CVE-2023-41900
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
Cloud Pak for Network Automation - update to 2.7.2
DataStage on Cloud Pak for Data - update to 5.0.0
Rational Change - update to 5.3.2.7
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM Sterling Control Center - update to 6.2.1.0.15
Fuse - update to 7.12.1
Rational Service Tester - update to 11.0.0
Rational Performance Tester - update to 11.0.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
IBM Automation Decision Services - update to 23.0.1 IF005
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-39
IBM Process Mining - update to 1.14.2.0.1
IBM MaaS360 Cloud Extender Agent - update to 3.000.300.025
IBM MaaS360 VPN Module - update to 3.000.400
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.400
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
User Entity Behavior Analytics - update to 5.0.2
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.0.0.2.159, 6.1.0.4.99, 6.2.0.7.5, 6.3.0.2.5
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.0.0.4.83, 6.1.0.2.79, 6.2.0.6.7, 6.3.0.2.6
IBM Secure External Authentication Server - addressed in versions 6.0.3.0 iFix 10, 6.1.0.0 iFix 06
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.22, 6.2.0.20, 6.3.0.5
UCD - IBM UrbanCode Deploy - addressed in versions 7.0.5.19, 7.1.2.15, 7.2.3.8, 7.3.2.3
Rational Synergy - update to 7.2.2.7
Storage Protect Server - update to 8.1.21
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 47, 8.11.0.1 Interim fix 25, 8.11.1 Interim fix 15, 8.12.0 Interim fix 6
jetty9 (Debian package) - addressed in versions 9.4.39-3+deb11u2, 9.4.50-4+deb12u1
jetty-xml - update to 9.4.53-150200.3.22.1
jetty-util - update to 9.4.53-150200.3.22.1
jetty-http - update to 9.4.53-150200.3.22.1
jetty-servlet - update to 9.4.53-150200.3.22.1
jetty-security - update to 9.4.53-150200.3.22.1
jetty-http-spi - update to 9.4.53-150200.3.22.1
jetty-io - update to 9.4.53-150200.3.22.1
jetty-util-ajax - update to 9.4.53-150200.3.22.1
jetty-cdi - update to 9.4.53-150200.3.22.1
jetty-servlets - update to 9.4.53-150200.3.22.1
jetty-rewrite - update to 9.4.53-150200.3.22.1
jetty-plus - update to 9.4.53-150200.3.22.1
jetty-minimal-javadoc - update to 9.4.53-150200.3.22.1
jetty-ant - update to 9.4.53-150200.3.22.1
jetty-openid - update to 9.4.53-150200.3.22.1
jetty-start - update to 9.4.53-150200.3.22.1
jetty-jmx - update to 9.4.53-150200.3.22.1
jetty-fcgi - update to 9.4.53-150200.3.22.1
jetty-webapp - update to 9.4.53-150200.3.22.1
jetty-proxy - update to 9.4.53-150200.3.22.1
jetty-continuation - update to 9.4.53-150200.3.22.1
jetty-jsp - update to 9.4.53-150200.3.22.1
jetty-deploy - update to 9.4.53-150200.3.22.1
jetty-client - update to 9.4.53-150200.3.22.1
jetty-jaas - update to 9.4.53-150200.3.22.1
jetty-server - update to 9.4.53-150200.3.22.1
jetty-jndi - update to 9.4.53-150200.3.22.1
jetty-quickstart - update to 9.4.53-150200.3.22.1
jetty-annotations - update to 9.4.53-150200.3.22.1
IBM Cognos Command Center - update to 10.2.5
Rational Functional Tester (RFT) - update to 11.0.0
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4
IBM Content Collector for SAP Applications - update to 21.0.3 IF031
External References
Related Security Bulletins
- Multiple vulnerabilities in Eclipse Jetty
- Debian update for jetty9
- Multiple vulnerabilities in IBM Process Mining
- SUSE update for jetty-minimal
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in Red Hat Fuse 7.12
- IBM Sterling Connect:Direct Web Services update for Eclipse Jetty
- IBM Sterling Connect Direct Browser User Interface update for Eclipse Jetty
- Multiple vulnerabilities in IBM Rational Functional Tester (RFT)
- Multiple vulnerabilities in IBM Automation Decision Services
- IBM UrbanCode Deploy (UCD) update for several Eclipse Jetty vulnerabilities
- IBM Storage Protect Server update for Eclipse Jetty
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM Sterling Connect:Direct for Microsoft Windows
- Multiple vulnerabilities in IBM Sterling Connect:Direct for UNIX
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender Agent, Mobile Enterprise Gateway and VPN Module
- Multiple vulnerabilities in IBM Rational Performance Tester
- Multiple vulnerabilities in IBM Rational Service Tester
- Multiple vulnerabilities in IBM Secure External Authentication Server
- Multiple vulnerabilities in IBM Secure Proxy
- Multiple vulnerabilities in IBM Operations Analytics Predictive Insights
- Multiple vulnerabilities in IBM Content Collector for SAP Applications
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Rational Change
- Multiple vulnerabilities in IBM Rational Synergy
- Multiple vulnerabilities in IBM Cognos Analytics
- IBM Sterling B2B Integrator update for Eclipse Jetty
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in IBM User Entity Behavior Analytics