Exposed dangerous method or function in Apache Tomcat - CVE-2023-42794
Published: October 10, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to Tomcat's internal fork of a Commons FileUpload included an unreleased, in progress refactoring that exposed a potential denial of service on Windows. A remote attacker can perform a denial of service attack by uploading multiple files to the server that are not removed.
Affected software
JBoss Web Server
Confluence Server
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Server
SUSE Enterprise Storage
Anolis OS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Web and Scripting Module
openSUSE Leap
Communications Unified Assurance
IBM App Connect Professional
Fuse
Confluence Data Center
Jira Software Data Center
IBM Rational Build Forge
Bamboo Server
IBM Integration Bus
EasyApache
IBM Sterling B2B Integrator
IBM UrbanCode Release
UCD - IBM UrbanCode Deploy
Jira Software Server
IBM Security Guardium
Tomcat
tomcat-webapps
tomcat-admin-webapps
tomcat-docs-webapp
tomcat-el-3.0-api
tomcat-jsp-2.3-api
tomcat-lib
tomcat-servlet-4.0-api
tomcat
tomcat-doc
tomcat-javadoc
tomcat-el-3_0-api
tomcat-servlet-4_0-api
tomcat-jsvc
tomcat-jsp-2_3-api
tomcat-embed
IBM Data Risk Manager
Storage Resource Manager
UrbanCode Build
EMC Cloud Tiering Appliance
Dell EMC Storage Monitoring and Reporting (SMR)
Operational Decision Manager
How to mitigate CVE-2023-42794
JBoss Web Server - update to 5.7.7
Fuse - update to 7.12.1
Confluence Server - addressed in versions 7.19.16, 8.5.3, 8.6.1
Confluence Data Center - addressed in versions 7.19.16, 8.5.3, 8.6.1
Jira Software Data Center - addressed in versions 8.20.28, 9.4.12, 9.11.3
IBM Rational Build Forge - update to 8.0.0.25
Jira Software Server - addressed in versions 8.20.28, 9.4.12, 9.11.3
Bamboo Server - addressed in versions 9.2.7, 9.3.5
Tomcat - update to D.9.0.87.01
IBM Data Risk Manager - update to 2.0.6.20
Storage Resource Manager - update to 4.10.0.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
EasyApache - update to 4 2023-10-12
IBM Sterling B2B Integrator - update to 6.2.0.1
IBM UrbanCode Release - update to 7.0.0
UrbanCode Build - update to 7.0.0
UCD - IBM UrbanCode Deploy - addressed in versions 7.0.5.19, 7.1.2.15, 7.2.3.8, 7.3.2.3
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 47, 8.11.0.1 Interim fix 25, 8.11.1 Interim fix 15, 8.12.0 Interim fix 6
tomcat-webapps - addressed in versions 9.0.62-30, 9.0.84-1
tomcat-admin-webapps - addressed in versions 9.0.62-30, 9.0.84-1
tomcat-docs-webapp - addressed in versions 9.0.62-30, 9.0.84-1
tomcat-el-3.0-api - addressed in versions 9.0.62-30, 9.0.84-1
tomcat-jsp-2.3-api - addressed in versions 9.0.62-30, 9.0.84-1
tomcat-lib - addressed in versions 9.0.62-30, 9.0.84-1
tomcat-servlet-4.0-api - addressed in versions 9.0.62-30, 9.0.84-1
tomcat - addressed in versions 9.0.62-30, 9.0.84-1
tomcat-doc - update to 9.0.84-1
tomcat - update to 9.0.85-150200.57.1
tomcat-javadoc - update to 9.0.85-150200.57.1
tomcat-lib - update to 9.0.85-150200.57.1
tomcat-el-3_0-api - update to 9.0.85-150200.57.1
tomcat-servlet-4_0-api - update to 9.0.85-150200.57.1
tomcat-webapps - update to 9.0.85-150200.57.1
tomcat-jsvc - update to 9.0.85-150200.57.1
tomcat-docs-webapp - update to 9.0.85-150200.57.1
tomcat-jsp-2_3-api - update to 9.0.85-150200.57.1
tomcat-embed - update to 9.0.85-150200.57.1
tomcat-admin-webapps - update to 9.0.85-150200.57.1
EMC Cloud Tiering Appliance - update to 13.1.0.2.35
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Tomcat
- Multiple vulnerabilities in cPanel EasyApache
- Multiple vulnerabilities in IBM Integration Bus
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in third-party components in Jira Software Data Center and Server
- Multiple vulnerabilities in Red Hat Fuse 7.12
- Bamboo Data Center and Server update for Apache Tomcat
- Confluence Data Center and Server update for Apache Tomcat
- Multiple vulnerabilities in IBM Rational Build Forge
- Dell EMC Cloud Tiering Appliance update for third-party software
- Multiple vulnerabilities in Red Hat JBoss Web Server 5.7
- Multiple vulnerabilities in IBM UrbanCode Deploy (UCD)
- App Connect Professional update for Apache Tomcat
- IBM Integration Bus update for Apache Tomcat
- IBM UrbanCode Build update for Apache Tomcat
- IBM UrbanCode Release update for Apache Tomcat
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in IBM Data Risk Manager
- SUSE update for tomcat
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- HP-UX update for Tomcat
- Anolis OS update for tomcat
- Anolis OS update for tomcat