Resource exhaustion in Logback - CVE-2023-6481

 

Resource exhaustion in Logback - CVE-2023-6481

Published: January 29, 2024


Vulnerability identifier: #VU85848
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-6481
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in logback receiver component. A remote attacker can send send poisoned data, trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Logback
IBM Business Automation Workflow
IBM Operations Analytics Predictive Insights
PowerVC
Bitbucket Data Center
Log Analysis
Netcool Operations Insight
IBM Process Mining
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Maximo Asset Management
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
IBM Observability with Instana
Red Hat OpenShift Serverless
DataStax Hyper-Converged Database
Cloud Pak for Network Automation
IBM i Modernization Engine for Lifecycle Integration
Storage Copy Data Management
IBM Cloud Pak for Watson AIOps
Storage Protect Server
Storage Virtualize
watsonx.data
Red Hat Camel for Spring Boot
Bitbucket Server
AMQ Broker
Fuse
openEuler
logback-examples
logback-help
logback-access
logback

How to mitigate CVE-2023-6481

Install updates from vendor's website.

Logback - addressed in versions 1.2.13, 1.3.14, 1.4.14
Red Hat OpenShift Serverless - update to 1.31.1
DataStax Hyper-Converged Database - update to 1.2.5
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
watsonx.data - update to 2.0.2
Cloud Pak for Network Automation - update to 2.7.2
Red Hat Camel for Spring Boot - update to 4.0.3
Bitbucket Server - addressed in versions 7.21.19, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0
Bitbucket Data Center - addressed in versions 7.21.19, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0
logback-examples - update to 1.2.8-3
logback-help - update to 1.2.8-3
logback-access - update to 1.2.8-3
logback - update to 1.2.8-3
Log Analysis - update to 1.3.8.1 IF001
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.6
Netcool Operations Insight - update to 1.6.12
IBM Process Mining - update to 1.14.3
Storage Copy Data Management - update to 2.2.24.1
QRadar User Behavior Analytics - update to 4.1.16
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.3
IBM Maximo Asset Management - update to 7.6.1.3.16
AMQ Broker - update to 7.12.0
Fuse - update to 7.13.0
Storage Protect Server - update to 8.1.22
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
IBM Maximo Application Suite - addressed in versions 8.10.7, 8.11.4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6
IBM Observability with Instana - update to 266

External References

Related Security Bulletins