Resource exhaustion in get-func-name - CVE-2023-43646

 

Resource exhaustion in get-func-name - CVE-2023-43646

Published: November 17, 2023


Vulnerability identifier: #VU83242
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43646
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when parsing malicious input. A remote attacker can trigger resource exhaustion when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly, and perform a denial of service (DoS) attack.


Affected software

get-func-name
IBM Cloud Pak for Multicloud Management
IBM Business Automation Manager Open Editions
Business Automation Insights
Dell Data Protection Central
IBM Cloud Pak for Business Automation
IBM Observability with Instana
IBM DB2
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2023-43646

Install update from vendor's website.

get-func-name - update to 2.0.1
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Business Automation Manager Open Editions - update to 9.0.1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM DB2 - update to 4.8
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.16.0
Dell Data Protection Central - update to 19.10.0-4
IBM Observability with Instana - update to 265

External References

Related Security Bulletins