Server-Side Request Forgery (SSRF) in Axis - CVE-2023-51441
Published: January 25, 2024
Vulnerability details
The disclosed vulnerability allows a remote user to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input in the service admin HTTP API. A remote user can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
IBM Sterling B2B Integrator
IBM Cloud Pak for Business Automation
IBM Tivoli Application Dependency Discovery Manager
Oracle Hospitality Reporting and Analytics
Storage Copy Data Management
IBM FileNet Content Manager
How to mitigate CVE-2023-51441
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
Storage Copy Data Management - update to 2.2.23.0
IBM FileNet Content Manager - addressed in versions 5.5.8.0 IF009, 5.5.12.0 IF004, 5.6.0.0 IF002
External References
Related Security Bulletins
- SSRF in Apache Axis
- Multiple vulnerabilities in IBM Storage Copy Data Management
- IBM B2B Sterling Integrator update for Apache Axis
- IBM Tivoli Application Dependency Discovery Manager update for Apache Axis
- IBM FileNet Content Manager in Apache Axis
- Multiple vulnerabilities in Oracle Hospitality Reporting and Analytics
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation