Resource exhaustion in Vault Enterprise and Vault - CVE-2023-6337
Published: December 11, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling large unauthenticated and authenticated HTTP requests from a client. A remote attacker can send large HTTP requests to the application, consume all available memory resources and perform a denial of service (DoS) attack.
Affected software
Vault
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2023-6337
Vault - addressed in versions 1.13.12, 1.14.8, 1.15.4
IBM Cloud Pak for Watson AIOps - update to 4.6.0