Allocation of Resources Without Limits or Throttling in snappy-java - CVE-2023-43642
Published: October 26, 2023 / Updated: March 21, 2024
Vulnerability identifier: #VU82454
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43642
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to missing upper bound check on chunk length. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
snappy-java
Guardium Data Security Center (GDSC)
Cloudera Observability with IBM
IBM Cloud Pak for Watson AIOps
Oracle Business Intelligence Enterprise Edition
Db2 Big SQL
IBM OpenPages with Watson
IBM Engineering Requirements Management DOORS Next
IBM Security Verify Information Queue
dashDB Local
DataPower Operations Dashboard
IBM Application Suite - IBM Asset Data Dictionary Component
ObjectScale
Cloud Pak for Network Automation
IBM Business Automation Manager Open Editions
Storage Protect Server
Telco Service Activator
webMethods BPM
InfoSphere Data Replication
IBM Operator for Apache Flink
IBM Operations Analytics Predictive Insights
IBM Security Guardium Key Lifecycle Manager (GKLM)
Red Hat build of Quarkus
IBM Intelligent Operations Center
Bitbucket Data Center
WebSphere Remote Server
IBM Maximo Application Suite
Jira Software Data Center
IBM Security Verify Governance
IBM Integration Bus
Log Analysis
Netcool Operations Insight
IBM Process Mining
IBM Spectrum Copy Data Management
IBM Cloud Object Storage Systems
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Sterling B2B Integrator
IBM Tivoli Business Service Manager
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
HPE Telco IP Mediation E-Media
IBM Maximo Application Suite - Manage Component
IBM Spectrum Protect Plus
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Observability with Instana
watsonx.data
IBM Db2 Web Query for i
IBM Data Risk Manager
Juniper Secure Analytics (JSA)
Splunk Enterprise
Bitbucket Server
AMQ Streams
Jira Software Server
IBM Qradar SIEM
Event Streams
IBM App Connect Enterprise
IBM DB2
IBM InfoSphere Information Server
IBM Security Guardium
openEuler
snappy-java
snappy-java-javadoc
IBM Disconnected Log Collector
IBM Cloud Pak System
Guardium Data Security Center (GDSC)
Cloudera Observability with IBM
IBM Cloud Pak for Watson AIOps
Oracle Business Intelligence Enterprise Edition
Db2 Big SQL
IBM OpenPages with Watson
IBM Engineering Requirements Management DOORS Next
IBM Security Verify Information Queue
dashDB Local
DataPower Operations Dashboard
IBM Application Suite - IBM Asset Data Dictionary Component
ObjectScale
Cloud Pak for Network Automation
IBM Business Automation Manager Open Editions
Storage Protect Server
Telco Service Activator
webMethods BPM
InfoSphere Data Replication
IBM Operator for Apache Flink
IBM Operations Analytics Predictive Insights
IBM Security Guardium Key Lifecycle Manager (GKLM)
Red Hat build of Quarkus
IBM Intelligent Operations Center
Bitbucket Data Center
WebSphere Remote Server
IBM Maximo Application Suite
Jira Software Data Center
IBM Security Verify Governance
IBM Integration Bus
Log Analysis
Netcool Operations Insight
IBM Process Mining
IBM Spectrum Copy Data Management
IBM Cloud Object Storage Systems
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Sterling B2B Integrator
IBM Tivoli Business Service Manager
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
HPE Telco IP Mediation E-Media
IBM Maximo Application Suite - Manage Component
IBM Spectrum Protect Plus
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Observability with Instana
watsonx.data
IBM Db2 Web Query for i
IBM Data Risk Manager
Juniper Secure Analytics (JSA)
Splunk Enterprise
Bitbucket Server
AMQ Streams
Jira Software Server
IBM Qradar SIEM
Event Streams
IBM App Connect Enterprise
IBM DB2
IBM InfoSphere Information Server
IBM Security Guardium
openEuler
snappy-java
snappy-java-javadoc
IBM Disconnected Log Collector
IBM Cloud Pak System
How to mitigate CVE-2023-43642
Install updates from vendor's website.
snappy-java - update to 1.1.10.4
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
watsonx.data - update to 2.0.2
Red Hat build of Quarkus - addressed in versions 2.13.9, 3.2.9
Guardium Data Security Center (GDSC) - addressed in versions 3.6.1, 3.8.5
Cloudera Observability with IBM - update to 3.6.2
Db2 Big SQL - update to 7.6.2
Juniper Secure Analytics (JSA) - addressed in versions 7.5.0 UP7 IF04, 7.5.0 UP7 IF05
Bitbucket Server - addressed in versions 7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0
Bitbucket Data Center - addressed in versions 7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0
IBM Maximo Application Suite - addressed in versions 8.10.6, 8.11.1
Jira Software Server - addressed in versions 9.4.16, 9.12.3
Splunk Enterprise - addressed in versions 9.0.9, 9.1.4, 9.2.1
Jira Software Data Center - addressed in versions 9.4.16, 9.12.3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
IBM Security Verify Information Queue - update to 10.0.7
IBM Integration Bus - update to 10.1.0.2
IBM App Connect Enterprise - addressed in versions 11.0.0.23, 12.0.10.1
dashDB Local - update to 11.5.9.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
DataPower Operations Dashboard - update to 1.0.20.1
snappy-java - update to 1.1.2.4-3
snappy-java-javadoc - update to 1.1.2.4-3
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.8
Log Analysis - update to 1.3.8 Fix Pack 1
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.11
IBM Disconnected Log Collector - update to 1.8.4
IBM Process Mining - update to 1.14.2.0.1
IBM Data Risk Manager - update to 2.0.6.20
IBM Spectrum Copy Data Management - update to 2.2.22
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
AMQ Streams - addressed in versions 2.5.2, 2.7.0
Cloud Pak for Network Automation - update to 2.6.4
IBM Cloud Object Storage Systems - addressed in versions 3.17.0.124, 3.17.5.86
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.4
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
App Connect Enterprise Certified Container - addressed in versions 5.0.12, 10.1.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
IBM Tivoli Business Service Manager - update to 6.2.0.5.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF05
IBM Maximo Asset Management - update to 7.6.1.3.16
IBM Business Automation Manager Open Editions - update to 8.0.6
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Server - update to 8.1.22
HPE Telco IP Mediation E-Media - update to 8.5.0
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.9, 8.7.4
Telco Service Activator - update to 10.1.1
IBM Spectrum Protect Plus - update to 10.1.6.4
webMethods BPM - update to 11.1 Fix 9
Event Streams - update to 11.4.0
InfoSphere Data Replication - update to 11.4.0.5.5702
IBM Business Automation Workflow - addressed in versions 21.0.3 IF029, 23.0.2 IF001
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.29, 23.0.2.1
IBM Observability with Instana - update to 283
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
watsonx.data - update to 2.0.2
Red Hat build of Quarkus - addressed in versions 2.13.9, 3.2.9
Guardium Data Security Center (GDSC) - addressed in versions 3.6.1, 3.8.5
Cloudera Observability with IBM - update to 3.6.2
Db2 Big SQL - update to 7.6.2
Juniper Secure Analytics (JSA) - addressed in versions 7.5.0 UP7 IF04, 7.5.0 UP7 IF05
Bitbucket Server - addressed in versions 7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0
Bitbucket Data Center - addressed in versions 7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0
IBM Maximo Application Suite - addressed in versions 8.10.6, 8.11.1
Jira Software Server - addressed in versions 9.4.16, 9.12.3
Splunk Enterprise - addressed in versions 9.0.9, 9.1.4, 9.2.1
Jira Software Data Center - addressed in versions 9.4.16, 9.12.3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
IBM Security Verify Information Queue - update to 10.0.7
IBM Integration Bus - update to 10.1.0.2
IBM App Connect Enterprise - addressed in versions 11.0.0.23, 12.0.10.1
dashDB Local - update to 11.5.9.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
DataPower Operations Dashboard - update to 1.0.20.1
snappy-java - update to 1.1.2.4-3
snappy-java-javadoc - update to 1.1.2.4-3
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.8
Log Analysis - update to 1.3.8 Fix Pack 1
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.11
IBM Disconnected Log Collector - update to 1.8.4
IBM Process Mining - update to 1.14.2.0.1
IBM Data Risk Manager - update to 2.0.6.20
IBM Spectrum Copy Data Management - update to 2.2.22
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
AMQ Streams - addressed in versions 2.5.2, 2.7.0
Cloud Pak for Network Automation - update to 2.6.4
IBM Cloud Object Storage Systems - addressed in versions 3.17.0.124, 3.17.5.86
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.4
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
App Connect Enterprise Certified Container - addressed in versions 5.0.12, 10.1.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
IBM Tivoli Business Service Manager - update to 6.2.0.5.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF05
IBM Maximo Asset Management - update to 7.6.1.3.16
IBM Business Automation Manager Open Editions - update to 8.0.6
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Server - update to 8.1.22
HPE Telco IP Mediation E-Media - update to 8.5.0
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.9, 8.7.4
Telco Service Activator - update to 10.1.1
IBM Spectrum Protect Plus - update to 10.1.6.4
webMethods BPM - update to 11.1 Fix 9
Event Streams - update to 11.4.0
InfoSphere Data Replication - update to 11.4.0.5.5702
IBM Business Automation Workflow - addressed in versions 21.0.3 IF029, 23.0.2 IF001
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.29, 23.0.2.1
IBM Observability with Instana - update to 283
External References
Related Security Bulletins
- Multiple vulnerabilities in IBM Process Mining
- Allocation of resources without limits or throttling in IBM Cloud Object System
- Allocation of resources without limits or throttling in IBM App Connect Enterprise Certified Container
- Allocation of resources without limits or throttling in IBM App Connect Enterprise and IBM Integration Bus
- Allocation of resources without limits or throttling in IBM Watson Assistant for IBM Cloud Pak for Data
- IBM InfoSphere Information Server update for snappy-java
- Multiple vulnerabilities in Red Hat build of Quarkus 3.2
- IBM Operator for Apache Flink update for snappy-java
- Multiple vulnerabilities in IBM DB2
- IBM Maximo Application Suite - Monitor Component update for Snappy-java
- Multiple vulnerabilities in Red Hat build of Quarkus 2.13
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Security Guardium
- IBM Security Verify Information Queue update for snappy-java
- Multiple vulnerabilities in IBM Spectrum Copy Data Management
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in IBM Disconnected Log Collector
- Multiple vulnerabilities in IBM Data Risk Manager
- Juniper Networks Juniper Secure Analytics update for third-party applications
- Allocation of resources without limits or throttling in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Allocation of resources without limits or throttling in IBM Maximo Application Suite - Manage Component
- Allocation of resources without limits or throttling in IBM Maximo Asset Management
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Allocation of resources without limits or throttling in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- openEuler update for snappy-java
- Allocation of resources without limits or throttling in IBM DataPower Operations Dashboard
- Multiple vulnerabilities in IBM Db2 Web Query for i
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Jira Software Data Center and Server update for snappy-java
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Operations Analytics Predictive Insights
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM OpenPages with Watson
- Multiple vulnerabilities in IBM Tivoli Business Service Manager
- Allocation of resources without limits or throttling in IBM Sterling B2B Integrator
- Multiple vulnerabilities in HPE Telco IP Mediation E-Media
- Multiple vulnerabilities in IBM Security Guardium Key Lifecycle Manager
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Multiple vulnerabilities in IBM Intelligent Operations Center (IOC)
- Multiple vulnerabilities in AMQ Streams 2.7
- Multiple vulnerabilities in IBM Asset Data Dictionary Component
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Security Verify Governance
- Allocation of Resources Without Limits or Throttling in Event Streams
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in AMQ Streams 2.5
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in IBM dashDB Local
- IBM InfoSphere Data Replication update for snappy-java
- Multiple vulnerabilities in IBM Knowledge Catalog for IBM Cloud Pak for Data
- Multiple vulnerabilities in HPE Telco Service Activator
- Multiple vulnerabilities in Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Bitbucket Data Center and Server update for org.xerial.snappy:snappy-java
- Multiple vulnerabilities in IBM Big SQL on IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM webMethods BPM