Allocation of Resources Without Limits or Throttling in snappy-java - CVE-2023-43642

 

Allocation of Resources Without Limits or Throttling in snappy-java - CVE-2023-43642

Published: October 26, 2023 / Updated: March 21, 2024


Vulnerability identifier: #VU82454
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43642
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to missing upper bound check on chunk length. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

snappy-java
Guardium Data Security Center (GDSC)
Cloudera Observability with IBM
IBM Cloud Pak for Watson AIOps
Oracle Business Intelligence Enterprise Edition
Db2 Big SQL
IBM OpenPages with Watson
IBM Engineering Requirements Management DOORS Next
IBM Security Verify Information Queue
dashDB Local
DataPower Operations Dashboard
IBM Application Suite - IBM Asset Data Dictionary Component
ObjectScale
Cloud Pak for Network Automation
IBM Business Automation Manager Open Editions
Storage Protect Server
Telco Service Activator
webMethods BPM
InfoSphere Data Replication
IBM Operator for Apache Flink
IBM Operations Analytics Predictive Insights
IBM Security Guardium Key Lifecycle Manager (GKLM)
Red Hat build of Quarkus
IBM Intelligent Operations Center
Bitbucket Data Center
WebSphere Remote Server
IBM Maximo Application Suite
Jira Software Data Center
IBM Security Verify Governance
IBM Integration Bus
Log Analysis
Netcool Operations Insight
IBM Process Mining
IBM Spectrum Copy Data Management
IBM Cloud Object Storage Systems
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Sterling B2B Integrator
IBM Tivoli Business Service Manager
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
HPE Telco IP Mediation E-Media
IBM Maximo Application Suite - Manage Component
IBM Spectrum Protect Plus
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Observability with Instana
watsonx.data
IBM Db2 Web Query for i
IBM Data Risk Manager
Juniper Secure Analytics (JSA)
Splunk Enterprise
Bitbucket Server
AMQ Streams
Jira Software Server
IBM Qradar SIEM
Event Streams
IBM App Connect Enterprise
IBM DB2
IBM InfoSphere Information Server
IBM Security Guardium
openEuler
snappy-java
snappy-java-javadoc
IBM Disconnected Log Collector
IBM Cloud Pak System

How to mitigate CVE-2023-43642

Install updates from vendor's website.

snappy-java - update to 1.1.10.4
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
watsonx.data - update to 2.0.2
Red Hat build of Quarkus - addressed in versions 2.13.9, 3.2.9
Guardium Data Security Center (GDSC) - addressed in versions 3.6.1, 3.8.5
Cloudera Observability with IBM - update to 3.6.2
Db2 Big SQL - update to 7.6.2
Juniper Secure Analytics (JSA) - addressed in versions 7.5.0 UP7 IF04, 7.5.0 UP7 IF05
Bitbucket Server - addressed in versions 7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0
Bitbucket Data Center - addressed in versions 7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0
IBM Maximo Application Suite - addressed in versions 8.10.6, 8.11.1
Jira Software Server - addressed in versions 9.4.16, 9.12.3
Splunk Enterprise - addressed in versions 9.0.9, 9.1.4, 9.2.1
Jira Software Data Center - addressed in versions 9.4.16, 9.12.3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
IBM Security Verify Information Queue - update to 10.0.7
IBM Integration Bus - update to 10.1.0.2
IBM App Connect Enterprise - addressed in versions 11.0.0.23, 12.0.10.1
dashDB Local - update to 11.5.9.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
DataPower Operations Dashboard - update to 1.0.20.1
snappy-java - update to 1.1.2.4-3
snappy-java-javadoc - update to 1.1.2.4-3
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.8
Log Analysis - update to 1.3.8 Fix Pack 1
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.11
IBM Disconnected Log Collector - update to 1.8.4
IBM Process Mining - update to 1.14.2.0.1
IBM Data Risk Manager - update to 2.0.6.20
IBM Spectrum Copy Data Management - update to 2.2.22
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
AMQ Streams - addressed in versions 2.5.2, 2.7.0
Cloud Pak for Network Automation - update to 2.6.4
IBM Cloud Object Storage Systems - addressed in versions 3.17.0.124, 3.17.5.86
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.4
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
App Connect Enterprise Certified Container - addressed in versions 5.0.12, 10.1.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
IBM Tivoli Business Service Manager - update to 6.2.0.5.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF05
IBM Maximo Asset Management - update to 7.6.1.3.16
IBM Business Automation Manager Open Editions - update to 8.0.6
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Server - update to 8.1.22
HPE Telco IP Mediation E-Media - update to 8.5.0
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.9, 8.7.4
Telco Service Activator - update to 10.1.1
IBM Spectrum Protect Plus - update to 10.1.6.4
webMethods BPM - update to 11.1 Fix 9
Event Streams - update to 11.4.0
InfoSphere Data Replication - update to 11.4.0.5.5702
IBM Business Automation Workflow - addressed in versions 21.0.3 IF029, 23.0.2 IF001
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.29, 23.0.2.1
IBM Observability with Instana - update to 283

External References

Related Security Bulletins