Integer overflow in Jetty - CVE-2023-36478
Published: October 10, 2023 / Updated: October 12, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow in MetaDataBuilder.checkSize when handling HTTP/2 HPACK header values. A remote attacker can send specially crafted request to the server, trigger an integer overflow and crash the server.
Affected software
Confluence Server
IBM Business Automation Workflow
IBM Sterling Control Center
Confluence Data Center
Bitbucket Data Center
Bamboo Server
IBM Integration Bus
Oracle Communications Cloud Native Core Network Exposure Function
IBM Cloud Pak for Data System
Log Analysis
IBM Process Mining
IBM MaaS360 Cloud Extender Agent
IBM MaaS360 Mobile Enterprise Gateway
IBM Cloud Transformation Advisor
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Connect:Direct for UNIX
IBM Sterling Secure Proxy
IBM Sterling Connect:Direct Web Services
UCD - IBM UrbanCode Deploy
IBM Maximo Asset Management
HPE Telco IP Mediation E-Media
IBM Maximo Application Suite
Rational Functional Tester (RFT)
Rational Service Tester
IBM Observability with Instana
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
Cognos Dashboards on Cloud Pak for Data
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Tivoli Network Manager IP Edition
Rational Performance Tester
IBM Application Suite - IBM Asset Data Dictionary Component
Installation Manager
Packaging Utility
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
User Entity Behavior Analytics
IBM Sterling Connect:Direct for Microsoft Windows
IBM Secure External Authentication Server
Rational Synergy
Storage Protect Server
IBM Engineering Systems Design Rhapsody
webMethods BPM
Sterling Connect:Direct Browser User Interface
Rational Change
Oracle Unified Directory
IBM Integrated Analytics System
IBM Data Risk Manager
IBM Qradar SIEM
IBM Cognos Command Center
Event Streams
Juniper Secure Analytics (JSA)
Fuse
Bitbucket Server
IBM Security Guardium
IBM InfoSphere Information Server
watsonx.data
IBM MaaS360 VPN Module
jetty9 (Debian package)
jetty-util
jetty-http-spi
jetty-rewrite
jetty-ant
jetty-openid
jetty-start
jetty-servlets
jetty-fcgi
jetty-webapp
jetty-proxy
jetty-continuation
jetty-quickstart
jetty-annotations
jetty-jndi
jetty-minimal-javadoc
jetty-plus
jetty-xml
jetty-jmx
jetty-jsp
jetty-deploy
jetty-client
jetty-jaas
jetty-cdi
jetty-util-ajax
jetty-io
jetty-security
jetty-servlet
jetty-http
jetty-server
IBM Cognos Analytics
How to mitigate CVE-2023-36478
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-39
Cloud Pak for Network Automation - update to 2.7.2
IBM Cloud Pak for Watson AIOps - update to 4.10.0
Tivoli Network Manager IP Edition - update to 4.2.0.20
Rational Change - update to 5.3.2.7
IBM Sterling Control Center - update to 6.2.1.0.15
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF03
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF03
Fuse - addressed in versions 7.12.1, 7.13.0
Confluence Data Center - addressed in versions 7.19.20, 8.5.7, 8.8.1
Confluence Server - addressed in versions 7.19.20, 8.5.7
Bitbucket Data Center - addressed in versions 8.9.8, 8.13.4, 8.14.3, 8.15.2, 8.16.1
Bitbucket Server - addressed in versions 8.9.8, 8.13.4, 8.14.3, 8.15.2, 8.16.1
Bamboo Server - addressed in versions 9.2.8, 9.3.6, 9.4.2
Rational Performance Tester - update to 11.0.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
IBM Cloud Pak for Data System - update to 1.0.9.0
IBM Integrated Analytics System - update to 1.0.30.0
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.15
Log Analysis - update to 1.3.8 Fix Pack 1
Installation Manager - update to 1.10.1.1
Packaging Utility - update to 1.10.1.1
IBM Process Mining - update to 1.14.3
watsonx.data - update to 2.0.3
IBM Data Risk Manager - update to 2.0.6.20
IBM MaaS360 Cloud Extender Agent - update to 3.000.300.025
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.400
IBM MaaS360 VPN Module - update to 3.000.400
IBM Cloud Transformation Advisor - update to 3.8.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
User Entity Behavior Analytics - update to 5.0.2
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.0.0.2.159, 6.1.0.4.99, 6.2.0.7.5, 6.3.0.2.5
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.0.0.4.83, 6.1.0.2.79, 6.2.0.6.7, 6.3.0.2.6
IBM Secure External Authentication Server - addressed in versions 6.0.3.0 iFix 10, 6.1.0.0 iFix 06
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.22, 6.2.0.20, 6.3.0.5
UCD - IBM UrbanCode Deploy - addressed in versions 7.0.5.19, 7.1.2.15, 7.2.3.8, 7.3.2.3
Rational Synergy - update to 7.2.2.7
IBM Maximo Asset Management - update to 7.6.1.3.15
Storage Protect Server - update to 8.1.21
HPE Telco IP Mediation E-Media - update to 8.5.0
IBM Maximo Application Suite - addressed in versions 8.6.9, 8.7.4
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
jetty9 (Debian package) - addressed in versions 9.4.50-4+deb11u1, 9.4.50-4+deb12u2
jetty-util - update to 9.4.53-150200.3.22.1
jetty-http-spi - update to 9.4.53-150200.3.22.1
jetty-rewrite - update to 9.4.53-150200.3.22.1
jetty-ant - update to 9.4.53-150200.3.22.1
jetty-openid - update to 9.4.53-150200.3.22.1
jetty-start - update to 9.4.53-150200.3.22.1
jetty-servlets - update to 9.4.53-150200.3.22.1
jetty-fcgi - update to 9.4.53-150200.3.22.1
jetty-webapp - update to 9.4.53-150200.3.22.1
jetty-proxy - update to 9.4.53-150200.3.22.1
jetty-continuation - update to 9.4.53-150200.3.22.1
jetty-quickstart - update to 9.4.53-150200.3.22.1
jetty-annotations - update to 9.4.53-150200.3.22.1
jetty-jndi - update to 9.4.53-150200.3.22.1
jetty-minimal-javadoc - update to 9.4.53-150200.3.22.1
jetty-plus - update to 9.4.53-150200.3.22.1
jetty-xml - update to 9.4.53-150200.3.22.1
jetty-jmx - update to 9.4.53-150200.3.22.1
jetty-jsp - update to 9.4.53-150200.3.22.1
jetty-deploy - update to 9.4.53-150200.3.22.1
jetty-client - update to 9.4.53-150200.3.22.1
jetty-jaas - update to 9.4.53-150200.3.22.1
jetty-cdi - update to 9.4.53-150200.3.22.1
jetty-util-ajax - update to 9.4.53-150200.3.22.1
jetty-io - update to 9.4.53-150200.3.22.1
jetty-security - update to 9.4.53-150200.3.22.1
jetty-servlet - update to 9.4.53-150200.3.22.1
jetty-http - update to 9.4.53-150200.3.22.1
jetty-server - update to 9.4.53-150200.3.22.1
IBM Cognos Command Center - update to 10.2.5
webMethods BPM - addressed in versions 10.15 Fix 15, 11.1 Fix 3
Rational Functional Tester (RFT) - update to 11.0.0
Rational Service Tester - update to 11.0.0
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
Event Streams - update to 11.3.1
IBM Observability with Instana - update to 274
External References
Related Security Bulletins
- Remote denial of service in Eclipse Jetty
- SUSE update for jetty-minimal
- Debian update for jetty9
- Multiple vulnerabilities in IBM Business Automation Workflow
- Integer overflow in IBM Integration Bus
- Multiple vulnerabilities in IBM Sterling Connect:Direct Web Services
- Multiple vulnerabilities in IBM Sterling Connect Direct Browser User Interface
- Multiple vulnerabilities in Red Hat Fuse 7.12
- IBM InfoSphere Information Server update for Eclipse Jetty
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Rational Functional Tester (RFT)
- IBM UrbanCode Deploy (UCD) update for Eclipse Jetty
- IBM Storage Protect Server update for Eclipse Jetty
- IBM Process Mining update for Eclipse Jetty
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Exposure Function
- Multiple vulnerabilities in IBM Sterling Connect:Direct for Microsoft Windows
- Multiple vulnerabilities in IBM Maximo Asset Management
- Multiple vulnerabilities in IBM Sterling Connect:Direct for UNIX
- Multiple vulnerabilities in IBM Data Risk Manager
- Integer overflow in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Maximo Application Suite - Manage Component
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender Agent, Mobile Enterprise Gateway and VPN Module
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Rational Service Tester
- Multiple vulnerabilities in IBM Rational Performance Tester
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Multiple vulnerabilities in IBM Secure External Authentication Server
- Integer overflow in IBM Event Streams
- Integer overflow in IBM Operations Analytics - Log Analysis
- Bitbucket Data Center and Server update for Jetty
- Bamboo Data Center and Server update for Jetty
- Confluence Data Center and Server update for Jetty
- Multiple vulnerabilities in IBM Secure Proxy
- Multiple vulnerabilities in HPE Telco IP Mediation E-Media
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- Multiple vulnerabilities in Fuse 7.13
- Multiple vulnerabilities in IBM Observability with Instana
- Integer overflow in Oracle Unified Directory
- IBM watsonx.data update for Eclipse Jetty
- Multiple vulnerabilities in IBM Rational Change
- Multiple vulnerabilities in IBM Rational Synergy
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition (ITNM)
- IBM Integrated Analytics System update for Eclipse Jetty
- Multiple vulnerabilities in IBM Asset Data Dictionary Component
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in IBM Installation Manager and IBM Packaging Utility
- IBM Cloud Pak for Data System 1.0 update for Eclipse Jetty
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM User Entity Behavior Analytics
- Multiple vulnerabilities in IBM webMethods BPM