Resource management error in IBM WebSphere Application Server Liberty - CVE-2023-46158

 

Resource management error in IBM WebSphere Application Server Liberty - CVE-2023-46158

Published: October 24, 2023


Vulnerability identifier: #VU82350
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46158
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper resource expiration handling. A remote attacker can bypass implemented security restrictions.


Affected software

IBM WebSphere Application Server Liberty
IBM Cloud Pak for Multicloud Management
IBM Copy Services Manager
IBM Watson Explorer Foundational Components
IBM Watson Explorer Analytical Components
IBM Watson Explorer Deep Analytics Edition oneWEX
IBM Watson Explorer Deep Analytics Edition Analytical Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
IBM Tivoli Netcool Impact
IBM Common Licensing
IBM Match 360
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Spectrum Control
IBM Sterling B2B Integrator
IBM Spectrum Scale for IBM Elastic Storage Server
IBM Global High Availability Mailbox
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite
IBM Security Verify Governance
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM OpenPages with Watson
IBM InfoSphere Identity Insight
CICS Transaction Gateway for Multiplatforms
IBM Security Verify Bridge for Directory Sync
PowerVM NovaLink
Maximo Application Suite - Predict Component
IBM Virtualization Engine TS7700 3948-VED
Robotic Process Automation for Cloud Pak
Voice Gateway
IBM Spectrum Scale
IBM Storage Scale System
Operational Decision Manager
Virtualization Engine TS7700 3957-VED
IBM License Metric Tool
IBM Security Verify Access
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2023-46158

Install updates from vendor's website.

IBM WebSphere Application Server Liberty - update to 23.0.0.11
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Copy Services Manager - update to 6.3.10
IBM Tivoli Netcool Impact - update to 7.1.0.32
Voice Gateway - addressed in versions 1.0.8.9, 1.0.8.12
PowerVM NovaLink - addressed in versions 2.1.1-240119, 2.2.0-240119
IBM Match 360 - update to 4.8.3
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Spectrum Scale - addressed in versions 5.1.2.15, 5.1.9.2
IBM Spectrum Control - update to 5.4.12
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
IBM Spectrum Scale for IBM Elastic Storage Server - addressed in versions 6.1.2.9, 6.1.9.2
IBM Storage Scale System - addressed in versions 6.1.2.9, 6.1.9.2
IBM Global High Availability Mailbox - update to 6.2.0.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Maximo Application Suite - Predict Component - update to 8.9.1
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 53, 8.11.0.1 Interim fix 28, 8.11.1 Interim fix 20, 8.12.0.1 Interim fix 2
IBM Maximo Application Suite - addressed in versions 8.10.8, 8.11.5
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.53.1.21 VTD_EXEC.903, 8.54.1.27 VTD_EXEC.904
Virtualization Engine TS7700 3957-VED - addressed in versions 8.53.1.21 VTD_EXEC.903, 8.54.1.27 VTD_EXEC.904
IBM License Metric Tool - update to 9.2.34
IBM Security Verify Governance - update to 10.0.2.0.1
IBM Security Verify Access - update to 10.0.7.0
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix23, 11.1.0.0 ifix16
IBM Watson Explorer Foundational Components - update to 11.0.2.18
IBM Watson Explorer Analytical Components - update to 11.0.2.18
IBM CICS TX Standard - update to 11.1.0.0 ifix16
IBM Watson Explorer Deep Analytics Edition oneWEX - update to 12.0.3.14
IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.14
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.14
IBM Business Automation Workflow - addressed in versions 21.0.3 IF027, 23.0.1 IF005
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.27, 23.0.1.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.13, 23.0.13
IBM Robotic Process Automation - addressed in versions 21.0.7.13, 23.0.13

External References

Related Security Bulletins