Resource exhaustion in RabbitMQ Java Client Library - CVE-2023-46120

 

Resource exhaustion in RabbitMQ Java Client Library - CVE-2023-46120

Published: November 22, 2023


Vulnerability identifier: #VU83414
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46120
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. A remote attacker can send a very large Message causing a memory overflow and triggering an OOM Error to perform a denial of service (DoS) attack.


Affected software

RabbitMQ Java Client Library
Cognos Dashboards on Cloud Pak for Data
IBM Cloud Pak for Watson AIOps
Storage Copy Data Management
Cloud Pak for Network Automation
IBM Watson Discovery for IBM Cloud Pak for Data
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Qradar SIEM
watsonx.data
Operational Decision Manager

How to mitigate CVE-2023-46120

Install updates from vendor's website.

RabbitMQ Java Client Library - update to 5.18.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.0
Netcool Operations Insight - update to 1.6.12
watsonx.data - update to 2.0.3
Storage Copy Data Management - update to 2.2.24.0
Cloud Pak for Network Automation - update to 2.6.4
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 47, 8.11.0.1 Interim fix 25, 8.11.1 Interim fix 15, 8.12.0 Interim fix 6

External References

Related Security Bulletins