Improper Neutralization of Special Elements used in an Expression Language Statement in Jena - CVE-2023-32200
Published: December 14, 2023
Vulnerability identifier: #VU84414
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32200
CWE-ID: CWE-917
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to insufficient restrictions of called script functions in Apache Jena. A remote user can execute javascript code via a SPARQL query on the target system.
Affected software
Jena
IBM Integration Bus
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Integration Bus
IBM Watson Knowledge Catalog in Cloud Pak for Data
How to mitigate CVE-2023-32200
Install updates from vendor's website.
Jena - update to 4.9.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3