Integer overflow in Jetty - CVE-2023-36478

 

Integer overflow in Jetty - CVE-2023-36478

Published: October 10, 2023 / Updated: October 12, 2023


Vulnerability identifier: #VU81726
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-36478
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to integer overflow in MetaDataBuilder.checkSize when handling HTTP/2 HPACK header values. A remote attacker can send specially crafted request to the server, trigger an integer overflow and crash the server.


Affected software

Jetty
Confluence Server
IBM Business Automation Workflow
IBM Sterling Control Center
Confluence Data Center
Bitbucket Data Center
Bamboo Server
IBM Integration Bus
Oracle Communications Cloud Native Core Network Exposure Function
IBM Cloud Pak for Data System
Log Analysis
IBM Process Mining
IBM MaaS360 Cloud Extender Agent
IBM MaaS360 Mobile Enterprise Gateway
IBM Cloud Transformation Advisor
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Connect:Direct for UNIX
IBM Sterling Secure Proxy
IBM Sterling Connect:Direct Web Services
UCD - IBM UrbanCode Deploy
IBM Maximo Asset Management
HPE Telco IP Mediation E-Media
IBM Maximo Application Suite
Rational Functional Tester (RFT)
Rational Service Tester
IBM Observability with Instana
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
Cognos Dashboards on Cloud Pak for Data
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Tivoli Network Manager IP Edition
Rational Performance Tester
IBM Application Suite - IBM Asset Data Dictionary Component
Installation Manager
Packaging Utility
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
User Entity Behavior Analytics
IBM Sterling Connect:Direct for Microsoft Windows
IBM Secure External Authentication Server
Rational Synergy
Storage Protect Server
IBM Engineering Systems Design Rhapsody
webMethods BPM
Sterling Connect:Direct Browser User Interface
Rational Change
Oracle Unified Directory
IBM Integrated Analytics System
IBM Data Risk Manager
IBM Qradar SIEM
IBM Cognos Command Center
Event Streams
Juniper Secure Analytics (JSA)
Fuse
Bitbucket Server
IBM Security Guardium
IBM InfoSphere Information Server
watsonx.data
IBM MaaS360 VPN Module
jetty9 (Debian package)
jetty-util
jetty-http-spi
jetty-rewrite
jetty-ant
jetty-openid
jetty-start
jetty-servlets
jetty-fcgi
jetty-webapp
jetty-proxy
jetty-continuation
jetty-quickstart
jetty-annotations
jetty-jndi
jetty-minimal-javadoc
jetty-plus
jetty-xml
jetty-jmx
jetty-jsp
jetty-deploy
jetty-client
jetty-jaas
jetty-cdi
jetty-util-ajax
jetty-io
jetty-security
jetty-servlet
jetty-http
jetty-server
IBM Cognos Analytics

How to mitigate CVE-2023-36478

Install updates from vendor's website.

Jetty - addressed in versions 9.4.53.v20230927, 10.0.16, 11.0.16
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-39
Cloud Pak for Network Automation - update to 2.7.2
IBM Cloud Pak for Watson AIOps - update to 4.10.0
Tivoli Network Manager IP Edition - update to 4.2.0.20
Rational Change - update to 5.3.2.7
IBM Sterling Control Center - update to 6.2.1.0.15
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF03
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF03
Fuse - addressed in versions 7.12.1, 7.13.0
Confluence Data Center - addressed in versions 7.19.20, 8.5.7, 8.8.1
Confluence Server - addressed in versions 7.19.20, 8.5.7
Bitbucket Data Center - addressed in versions 8.9.8, 8.13.4, 8.14.3, 8.15.2, 8.16.1
Bitbucket Server - addressed in versions 8.9.8, 8.13.4, 8.14.3, 8.15.2, 8.16.1
Bamboo Server - addressed in versions 9.2.8, 9.3.6, 9.4.2
Rational Performance Tester - update to 11.0.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
IBM Cloud Pak for Data System - update to 1.0.9.0
IBM Integrated Analytics System - update to 1.0.30.0
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.15
Log Analysis - update to 1.3.8 Fix Pack 1
Installation Manager - update to 1.10.1.1
Packaging Utility - update to 1.10.1.1
IBM Process Mining - update to 1.14.3
watsonx.data - update to 2.0.3
IBM Data Risk Manager - update to 2.0.6.20
IBM MaaS360 Cloud Extender Agent - update to 3.000.300.025
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.400
IBM MaaS360 VPN Module - update to 3.000.400
IBM Cloud Transformation Advisor - update to 3.8.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
User Entity Behavior Analytics - update to 5.0.2
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.0.0.2.159, 6.1.0.4.99, 6.2.0.7.5, 6.3.0.2.5
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.0.0.4.83, 6.1.0.2.79, 6.2.0.6.7, 6.3.0.2.6
IBM Secure External Authentication Server - addressed in versions 6.0.3.0 iFix 10, 6.1.0.0 iFix 06
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.22, 6.2.0.20, 6.3.0.5
UCD - IBM UrbanCode Deploy - addressed in versions 7.0.5.19, 7.1.2.15, 7.2.3.8, 7.3.2.3
Rational Synergy - update to 7.2.2.7
IBM Maximo Asset Management - update to 7.6.1.3.15
Storage Protect Server - update to 8.1.21
HPE Telco IP Mediation E-Media - update to 8.5.0
IBM Maximo Application Suite - addressed in versions 8.6.9, 8.7.4
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
jetty9 (Debian package) - addressed in versions 9.4.50-4+deb11u1, 9.4.50-4+deb12u2
jetty-util - update to 9.4.53-150200.3.22.1
jetty-http-spi - update to 9.4.53-150200.3.22.1
jetty-rewrite - update to 9.4.53-150200.3.22.1
jetty-ant - update to 9.4.53-150200.3.22.1
jetty-openid - update to 9.4.53-150200.3.22.1
jetty-start - update to 9.4.53-150200.3.22.1
jetty-servlets - update to 9.4.53-150200.3.22.1
jetty-fcgi - update to 9.4.53-150200.3.22.1
jetty-webapp - update to 9.4.53-150200.3.22.1
jetty-proxy - update to 9.4.53-150200.3.22.1
jetty-continuation - update to 9.4.53-150200.3.22.1
jetty-quickstart - update to 9.4.53-150200.3.22.1
jetty-annotations - update to 9.4.53-150200.3.22.1
jetty-jndi - update to 9.4.53-150200.3.22.1
jetty-minimal-javadoc - update to 9.4.53-150200.3.22.1
jetty-plus - update to 9.4.53-150200.3.22.1
jetty-xml - update to 9.4.53-150200.3.22.1
jetty-jmx - update to 9.4.53-150200.3.22.1
jetty-jsp - update to 9.4.53-150200.3.22.1
jetty-deploy - update to 9.4.53-150200.3.22.1
jetty-client - update to 9.4.53-150200.3.22.1
jetty-jaas - update to 9.4.53-150200.3.22.1
jetty-cdi - update to 9.4.53-150200.3.22.1
jetty-util-ajax - update to 9.4.53-150200.3.22.1
jetty-io - update to 9.4.53-150200.3.22.1
jetty-security - update to 9.4.53-150200.3.22.1
jetty-servlet - update to 9.4.53-150200.3.22.1
jetty-http - update to 9.4.53-150200.3.22.1
jetty-server - update to 9.4.53-150200.3.22.1
IBM Cognos Command Center - update to 10.2.5
webMethods BPM - addressed in versions 10.15 Fix 15, 11.1 Fix 3
Rational Functional Tester (RFT) - update to 11.0.0
Rational Service Tester - update to 11.0.0
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
Event Streams - update to 11.3.1
IBM Observability with Instana - update to 274

External References

Related Security Bulletins