Inefficient Algorithmic Complexity in Werkzeug - CVE-2023-46136
Published: October 30, 2023
Vulnerability identifier: #VU82548
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46136
CWE-ID: CWE-407
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to high resource usage when parsing multipart/form-data. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Werkzeug
watsonx.data
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
Python 3 Module
openSUSE Leap
openEuler
IBM Concert Software
IBM Cloud Pak for Data System
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Network Repository Function
IBM Process Mining
Qradar Advisor
IBM Fusion HCI
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Maximo Application Suite
IBM Spectrum Protect Plus
QRadar Suite
Juniper Secure Analytics (JSA)
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Oracle Communications Operations Monitor
Storage Ceph
Maximo Application Suite - Visual Inspection Component
Storage Sentinel Anomaly Scan Engine
QRadar Assistant
IBM Cloud Pak for Watson AIOps
SOAR QRadar Plugin App
IBM QRadar Incident Forensics
Maximo Application Suite - Monitor Component
IBM Qradar SIEM
Cloud Pak for Data
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
python-eventlet (Red Hat package)
cri-o (Red Hat package)
python-werkzeug (Red Hat package)
python-werkzeug
python-werkzeug-help
python3-werkzeug
python-markupsafe (Red Hat package)
python311-Werkzeug
oath-toolkit (Red Hat package)
haproxy (Red Hat package)
cephadm-ansible (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
ceph (Red Hat package)
Red Hat Ceph Storage
IBM InfoSphere Information Server
watsonx.data
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
Python 3 Module
openSUSE Leap
openEuler
IBM Concert Software
IBM Cloud Pak for Data System
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Network Repository Function
IBM Process Mining
Qradar Advisor
IBM Fusion HCI
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Maximo Application Suite
IBM Spectrum Protect Plus
QRadar Suite
Juniper Secure Analytics (JSA)
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Oracle Communications Operations Monitor
Storage Ceph
Maximo Application Suite - Visual Inspection Component
Storage Sentinel Anomaly Scan Engine
QRadar Assistant
IBM Cloud Pak for Watson AIOps
SOAR QRadar Plugin App
IBM QRadar Incident Forensics
Maximo Application Suite - Monitor Component
IBM Qradar SIEM
Cloud Pak for Data
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
python-eventlet (Red Hat package)
cri-o (Red Hat package)
python-werkzeug (Red Hat package)
python-werkzeug
python-werkzeug-help
python3-werkzeug
python-markupsafe (Red Hat package)
python311-Werkzeug
oath-toolkit (Red Hat package)
haproxy (Red Hat package)
cephadm-ansible (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
ceph (Red Hat package)
Red Hat Ceph Storage
IBM InfoSphere Information Server
How to mitigate CVE-2023-46136
Install updates from vendor's website.
Werkzeug - update to 3.0.1
IBM Concert Software - update to 1.0.3
QRadar Suite - update to 1.10.21.0
IBM Cloud Pak for Data System - update to 2.0.2.1.IF2
watsonx.data - update to 2.3.1
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Red Hat OpenShift Container Platform - addressed in versions 4.12.45, 4.13.24
Storage Ceph - update to 8.1
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
Maximo Application Suite - Visual Inspection Component - update to 9.0.2
python-eventlet (Red Hat package) - update to 0.33.1-5.el9
Storage Sentinel Anomaly Scan Engine - update to 1.1.7
IBM Process Mining - update to 1.14.3
cri-o (Red Hat package) - addressed in versions 1.25.5-2.rhaos4.12.git0217273.el8, 1.27.2-2.rhaos4.14.git9d684e2.el8, 1.27.2-2.rhaos4.14.git9d684e2.el9
python-werkzeug (Red Hat package) - addressed in versions 2.0.3-5.el9, 2.2.3-2.el9
python-werkzeug - addressed in versions 2.0.3-6, 2.2.3-4
python-werkzeug-help - addressed in versions 2.0.3-6, 2.2.3-4
python3-werkzeug - addressed in versions 2.0.3-6, 2.2.3-4
python-markupsafe (Red Hat package) - update to 2.1.1-4.el9
python311-Werkzeug - update to 2.3.6-150400.6.6.1
Qradar Advisor - update to 2.6.6
oath-toolkit (Red Hat package) - update to 2.6.12-1.el9cp
haproxy (Red Hat package) - update to 2.6.13-2.rhaos4.14.el8
IBM Fusion HCI - update to 2.7.1
QRadar Assistant - update to 3.7.0
cephadm-ansible (Red Hat package) - update to 4.1.4-1.el9cp
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
Cloud Pak for Data - update to 4.8.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
openshift (Red Hat package) - addressed in versions 4.12.0-202311161331.p0.ga52e8df.assembly.stream.el8, 4.12.0-202311161331.p0.ga52e8df.assembly.stream.el9, 4.13.0-202311212009.p0.gaa37255.assembly.stream.el8, 4.13.0-202311212009.p0.gaa37255.assembly.stream.el9, 4.14.0-202311161233.p0.gd548052.assembly.stream.el8, 4.14.0-202311161233.p0.gd548052.assembly.stream.el9
openshift-clients (Red Hat package) - addressed in versions 4.12.0-202311221849.p0.gd2ac7e1.assembly.stream.el8, 4.12.0-202311221849.p0.gd2ac7e1.assembly.stream.el9
kernel (Red Hat package) - update to 4.18.0-372.82.1.el8_6
kernel-rt (Red Hat package) - update to 4.18.0-372.82.1.rt7.241.el8_6
SOAR QRadar Plugin App - update to 5.3.1
IBM QRadar Incident Forensics - update to 7.5.0.10
Red Hat Ceph Storage - update to 8.1
IBM Maximo Application Suite - addressed in versions 8.7.7, 8.10.8
Maximo Application Suite - Monitor Component - addressed in versions 8.10.13, 8.11.13, 9.0.5, 9.1.0
IBM Spectrum Protect Plus - update to 10.1.16
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
ceph (Red Hat package) - update to 19.2.1-222.el9cp
IBM Concert Software - update to 1.0.3
QRadar Suite - update to 1.10.21.0
IBM Cloud Pak for Data System - update to 2.0.2.1.IF2
watsonx.data - update to 2.3.1
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Red Hat OpenShift Container Platform - addressed in versions 4.12.45, 4.13.24
Storage Ceph - update to 8.1
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
Maximo Application Suite - Visual Inspection Component - update to 9.0.2
python-eventlet (Red Hat package) - update to 0.33.1-5.el9
Storage Sentinel Anomaly Scan Engine - update to 1.1.7
IBM Process Mining - update to 1.14.3
cri-o (Red Hat package) - addressed in versions 1.25.5-2.rhaos4.12.git0217273.el8, 1.27.2-2.rhaos4.14.git9d684e2.el8, 1.27.2-2.rhaos4.14.git9d684e2.el9
python-werkzeug (Red Hat package) - addressed in versions 2.0.3-5.el9, 2.2.3-2.el9
python-werkzeug - addressed in versions 2.0.3-6, 2.2.3-4
python-werkzeug-help - addressed in versions 2.0.3-6, 2.2.3-4
python3-werkzeug - addressed in versions 2.0.3-6, 2.2.3-4
python-markupsafe (Red Hat package) - update to 2.1.1-4.el9
python311-Werkzeug - update to 2.3.6-150400.6.6.1
Qradar Advisor - update to 2.6.6
oath-toolkit (Red Hat package) - update to 2.6.12-1.el9cp
haproxy (Red Hat package) - update to 2.6.13-2.rhaos4.14.el8
IBM Fusion HCI - update to 2.7.1
QRadar Assistant - update to 3.7.0
cephadm-ansible (Red Hat package) - update to 4.1.4-1.el9cp
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
Cloud Pak for Data - update to 4.8.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
openshift (Red Hat package) - addressed in versions 4.12.0-202311161331.p0.ga52e8df.assembly.stream.el8, 4.12.0-202311161331.p0.ga52e8df.assembly.stream.el9, 4.13.0-202311212009.p0.gaa37255.assembly.stream.el8, 4.13.0-202311212009.p0.gaa37255.assembly.stream.el9, 4.14.0-202311161233.p0.gd548052.assembly.stream.el8, 4.14.0-202311161233.p0.gd548052.assembly.stream.el9
openshift-clients (Red Hat package) - addressed in versions 4.12.0-202311221849.p0.gd2ac7e1.assembly.stream.el8, 4.12.0-202311221849.p0.gd2ac7e1.assembly.stream.el9
kernel (Red Hat package) - update to 4.18.0-372.82.1.el8_6
kernel-rt (Red Hat package) - update to 4.18.0-372.82.1.rt7.241.el8_6
SOAR QRadar Plugin App - update to 5.3.1
IBM QRadar Incident Forensics - update to 7.5.0.10
Red Hat Ceph Storage - update to 8.1
IBM Maximo Application Suite - addressed in versions 8.7.7, 8.10.8
Maximo Application Suite - Monitor Component - addressed in versions 8.10.13, 8.11.13, 9.0.5, 9.1.0
IBM Spectrum Protect Plus - update to 10.1.16
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
ceph (Red Hat package) - update to 19.2.1-222.el9cp
External References
Related Security Bulletins
- Denial of service in Werkzeug
- SUSE update for python-Werkzeug
- Red Hat OpenShift Container Platform 4.13 update for python-werkzeug
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12 for RHEL 9
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.14
- Inefficient algorithmic complexity in IBM Storage Fusion
- IBM Process Mining update for Pallets Werkzeug
- Inefficient algorithmic complexity in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM SOAR QRadar Plugin App
- Juniper Networks Juniper Secure Analytics update for third-party applications
- Inefficient algorithmic complexity in IBM Watson Discovery
- Multiple vulnerabilities in IBM Spectrum Protect Plus File Systems Agent
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Inefficient algorithmic complexity in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Inefficient algorithmic complexity in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM QRadar Assistant
- Multiple vulnerabilities in IBM QRadar Suite software
- Inefficient algorithmic complexity in IBM Cloud Pak for Data
- IBM Maximo Application Suite - Maximo Visual Inspection Component update for Werkzeug-2.2.3-py3-none-any.whl
- Multiple vulnerabilities in Oracle Communications Operations Monitor
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Automated Test Suite
- Multiple vulnerabilities in Oracle Communications Network Analytics Data Director
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in QRadar Incident Forensics
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in IBM Maximo Application Suite - Monitor Component
- Multiple vulnerabilities in QRadar Advisor With Watson for IBM QRadar SIEM
- IBM Cloud Pak for Data System 2.0 update for Pallets Werkzeug
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- Multiple vulnerabilities in IBM Storage Ceph
- openEuler 24.03 LTS SP1 update for python-werkzeug
- openEuler 24.03 LTS update for python-werkzeug
- openEuler 24.03 LTS SP1 update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 24.03 LTS update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 24.03 LTS SP1 update for python-werkzeug
- openEuler 24.03 LTS SP1 update for python-werkzeug
- openEuler 24.03 LTS SP1 update for python-werkzeug
- openEuler 24.03 LTS update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 24.03 LTS update for python-werkzeug
- openEuler 24.03 LTS SP2 update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 24.03 LTS update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 24.03 LTS SP1 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 24.03 LTS SP1 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 24.03 LTS SP2 update for python-werkzeug
- openEuler 24.03 LTS SP2 update for python-werkzeug
- openEuler 24.03 LTS SP2 update for python-werkzeug
- openEuler 24.03 LTS SP2 update for python-werkzeug
- openEuler 24.03 LTS update for python-werkzeug
- openEuler 24.03 LTS SP1 update for python-werkzeug
- openEuler 24.03 LTS update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 24.03 LTS SP2 update for python-werkzeug
- openEuler 24.03 LTS SP2 update for python-werkzeug
- Multiple vulnerabilities in IBM watsonx.data