Input validation error in Reactor Netty - CVE-2023-34054

 

Input validation error in Reactor Netty - CVE-2023-34054

Published: November 29, 2023


Vulnerability identifier: #VU83580
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34054
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send specially crafted HTTP requests to the application and perform a denial of service (DoS) attack.


Affected software

Reactor Netty
IBM Security Guardium
IBM Disconnected Log Collector
Storage Copy Data Management
Cloud Pak for Network Automation
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Dell Data Protection Central
Operational Decision Manager
IBM Observability with Instana

How to mitigate CVE-2023-34054

Install updates from vendor's website.

Reactor Netty - addressed in versions 1.0.39, 1.1.13
IBM Disconnected Log Collector - update to 1.8.5
Storage Copy Data Management - update to 2.2.27.0
Cloud Pak for Network Automation - update to 2.6.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 51, 8.11.0.1 Interim fix 27, 8.11.1 Interim fix 19, 8.12.0.1 Interim fix 1
Dell Data Protection Central - update to 19.11.0-2
IBM Observability with Instana - update to 266

External References

Related Security Bulletins