Improper input validation in Oracle Database Server - CVE-2023-35116

 

Improper input validation in Oracle Database Server - CVE-2023-35116

Published: October 17, 2023


Vulnerability identifier: #VU82122
CSH Severity: Low
CVSS v4 BT: 0.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-35116
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to perform service disruption.

The vulnerability exists due to improper input validation within the Oracle Database Fleet Patching and Provisioning (jackson-databind) in Oracle Database Server. A remote authenticated user can exploit this vulnerability to perform service disruption.


Affected software

Oracle Database Server
IBM DB2
Amazon Linux AMI
Migration Toolkit for Runtimes
IBM Sterling B2B Integrator
CICS Transaction Gateway
IBM Fusion HCI
Financial Transaction Manager for ACH Services and Check Services
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Sterling Connect:Direct Web Services
Red Hat Migration Toolkit for Applications
IBM Spectrum Symphony
IBM SPSS Collaboration and Deployment Services
IBM Security Verify Governance
EMC Data Protection Advisor
NetWorker
IBM Cloud Pak for Business Automation
IBM Observability with Instana
Oracle Business Intelligence Enterprise Edition
CICS Transaction Gateway for Multiplatforms
IBM Engineering Requirements Management DOORS Next
Oracle Data Integrator
ObjectScale
PowerStore T
Dell EMC PowerStore Family Operating System
DataStage on Cloud Pak for Data
User Entity Behavior Analytics
IBM Sterling Connect:Direct for Microsoft Windows
IBM Engineering Lifecycle Optimization - Publishing
IBM QRadar Incident Forensics
Db2 Big SQL
webMethods BPM
webMethods Integration Server
Juniper Secure Analytics (JSA)
Splunk Enterprise
Oracle Communications Pricing Design Center
Oracle WebLogic Server
AMQ Broker
Identity Manager
IBM Disconnected Log Collector
IBM Data Risk Manager
jackson-core
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
Red Hat Camel for Spring Boot
Jazz Reporting Service
IBM Qradar SIEM
Operational Decision Manager

How to mitigate CVE-2023-35116

Install updates from vendor's website.

Oracle Database Server - update to 19.3
Migration Toolkit for Runtimes - update to 1.2.4
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04
Splunk Enterprise - addressed in versions 9.0.9, 9.1.4, 9.2.1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
ObjectScale - update to 1.4.0
IBM Disconnected Log Collector - update to 1.8.4
IBM Data Risk Manager - update to 2.0.6.20
IBM Fusion HCI - update to 2.7.1
jackson-core - update to 2.11.4-7
jenkins (Red Hat package) - update to 2.426.3.1706516352-3.el8
Financial Transaction Manager for ACH Services and Check Services - update to 3.0.5.4 iFix 28
PowerStore T - update to 3.6.1.2-2315284
IBM Cloud Transformation Advisor - update to 3.10.0
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
Red Hat Camel for Spring Boot - update to 4.4.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
jenkins-2-plugins (Red Hat package) - update to 4.14.1706516441-1.el8
DataStage on Cloud Pak for Data - update to 5.0.0
IBM DB2 - update to 5.0
User Entity Behavior Analytics - update to 5.0.2
IBM Spectrum Control - update to 5.4.12
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.0.0.4.88, 6.1.0.2.87, 6.2.0.6.20, 6.3.0.3.4
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.23, 6.2.0.22
Red Hat Migration Toolkit for Applications - update to 6.2
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.1.23, 7.0.2.25
Jazz Reporting Service - update to 7.0.2 iFix022
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF02
IBM QRadar Incident Forensics - update to 7.5.0 UP10 IF02
Db2 Big SQL - update to 7.6.4
AMQ Broker - update to 7.12.0
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.22
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 54, 8.11.0.1 Interim fix 29, 8.11.1 Interim fix 21, 8.12.0.1 Interim fix 3
IBM Security Verify Governance - update to 10.0.2
webMethods BPM - update to 11.1 Fix 1
webMethods Integration Server - update to 11.1 Fix 1
EMC Data Protection Advisor - update to 19.10 B46
NetWorker - update to 19.10.0.3
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF034, 23.0.2-IF006
IBM Observability with Instana - update to 268

External References

Related Security Bulletins