Excessive Iteration in parsson - CVE-2023-4043

 

Excessive Iteration in parsson - CVE-2023-4043

Published: January 11, 2024


Vulnerability identifier: #VU85304
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-4043
CWE-ID: CWE-834
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect. A remote attacker can trigger excessive iteration and perform a denial of service (DoS) attack.


Affected software

parsson
IBM OpenPages with Watson
Event Processing
IBM Cloud Pak for Watson AIOps
IBM Event Endpoint Management
Cryostat
Red Hat build of Quarkus
Management Cloud Engine
IBM Process Mining
Red Hat Camel for Spring Boot
Oracle REST Data Services
IBM App Connect for Healthcare
JBoss Enterprise Application Platform
Communications Service Catalog and Design
PeopleSoft Enterprise PeopleTools
Oracle Retail EFTLink
eap8-parsson (Red Hat package)
eap8-apache-sshd (Red Hat package)
eap8-log4j (Red Hat package)
eap8-eclipse-jgit (Red Hat package)
eap8-wildfly (Red Hat package)
eap8-lucene-solr (Red Hat package)

How to mitigate CVE-2023-4043

Install updates from vendor's website.

parsson - addressed in versions 1.0.5, 1.1.4
Red Hat build of Quarkus - update to 3.2.10
Red Hat Camel for Spring Boot - update to 4.0.3
JBoss Enterprise Application Platform - update to 8.0.1
IBM OpenPages with Watson - update to 9.0.0.5.3
Oracle REST Data Services - update to 23.3.1
Event Processing - update to 1.1.1
eap8-parsson (Red Hat package) - addressed in versions 1.1.5-1.redhat_00001.1.el8eap, 1.1.5-1.redhat_00001.1.el9eap
IBM Process Mining - update to 1.14.3
eap8-apache-sshd (Red Hat package) - addressed in versions 2.12.0-1.redhat_00001.1.el8eap, 2.12.0-1.redhat_00001.1.el9eap
eap8-log4j (Red Hat package) - addressed in versions 2.19.0-2.redhat_00001.1.el8eap, 2.19.0-2.redhat_00001.1.el9eap
IBM Cloud Pak for Watson AIOps - update to 4.6.0
eap8-eclipse-jgit (Red Hat package) - addressed in versions 6.6.1.202309021850-1.r_redhat_00001.1.el8eap, 6.6.1.202309021850-1.r_redhat_00001.1.el9eap
eap8-wildfly (Red Hat package) - addressed in versions 8.0.1-3.GA_redhat_00002.1.el8eap, 8.0.1-3.GA_redhat_00002.1.el9eap
eap8-lucene-solr (Red Hat package) - addressed in versions 8.11.2-2.redhat_00001.1.el8eap, 8.11.2-2.redhat_00001.1.el9eap
IBM Event Endpoint Management - update to 11.1.1

External References

Related Security Bulletins