Resource exhaustion in get-func-name - CVE-2023-43646
Published: November 17, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing malicious input. A remote attacker can trigger resource exhaustion when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly, and perform a denial of service (DoS) attack.
Affected software
IBM Cloud Pak for Multicloud Management
IBM Business Automation Manager Open Editions
Business Automation Insights
Dell Data Protection Central
IBM Cloud Pak for Business Automation
IBM Observability with Instana
IBM DB2
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2023-43646
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Business Automation Manager Open Editions - update to 9.0.1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM DB2 - update to 4.8
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.16.0
Dell Data Protection Central - update to 19.10.0-4
IBM Observability with Instana - update to 265
External References
Related Security Bulletins
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Dell Data Protection Central update for third-party components
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation