Resource exhaustion in Logback - CVE-2023-6481
Published: January 29, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in logback receiver component. A remote attacker can send send poisoned data, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM Business Automation Workflow
IBM Operations Analytics Predictive Insights
PowerVC
Bitbucket Data Center
Log Analysis
Netcool Operations Insight
IBM Process Mining
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Maximo Asset Management
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
IBM Observability with Instana
Red Hat OpenShift Serverless
DataStax Hyper-Converged Database
Cloud Pak for Network Automation
IBM i Modernization Engine for Lifecycle Integration
Storage Copy Data Management
IBM Cloud Pak for Watson AIOps
Storage Protect Server
Storage Virtualize
watsonx.data
Red Hat Camel for Spring Boot
Bitbucket Server
AMQ Broker
Fuse
openEuler
logback-examples
logback-help
logback-access
logback
How to mitigate CVE-2023-6481
Red Hat OpenShift Serverless - update to 1.31.1
DataStax Hyper-Converged Database - update to 1.2.5
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
watsonx.data - update to 2.0.2
Cloud Pak for Network Automation - update to 2.7.2
Red Hat Camel for Spring Boot - update to 4.0.3
Bitbucket Server - addressed in versions 7.21.19, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0
Bitbucket Data Center - addressed in versions 7.21.19, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0
logback-examples - update to 1.2.8-3
logback-help - update to 1.2.8-3
logback-access - update to 1.2.8-3
logback - update to 1.2.8-3
Log Analysis - update to 1.3.8.1 IF001
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.6
Netcool Operations Insight - update to 1.6.12
IBM Process Mining - update to 1.14.3
Storage Copy Data Management - update to 2.2.24.1
QRadar User Behavior Analytics - update to 4.1.16
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.3
IBM Maximo Asset Management - update to 7.6.1.3.16
AMQ Broker - update to 7.12.0
Fuse - update to 7.13.0
Storage Protect Server - update to 8.1.22
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
IBM Maximo Application Suite - addressed in versions 8.10.7, 8.11.4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6
IBM Observability with Instana - update to 266
External References
Related Security Bulletins
- Resource exhaustion in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in Red Hat Integration Camel for Spring Boot 4.0
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Maximo Application Suite - Monitor Component
- Resource exhaustion in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Maximo Asset Management
- Multiple vulnerabilities in IBM i Modernization Engine for Lifecycle Integration
- openEuler update for logback
- Resource exhaustion in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM Operations Analytics Predictive Insights
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Multiple vulnerabilities in AMQ Broker 7.12
- Multiple vulnerabilities in Fuse 7.13
- Multiple vulnerabilities in IBM Storage Virtualize
- Resource exhaustion in PowerVC
- Resource exhaustion in IBM watsonx.data
- Multiple vulnerabilities in IBM Storage Copy Data Management
- IBM Operations Analytics - Log Analysis update for QOS.ch Sarl Logback
- Bitbucket Data Center and Server update for ch.qos.logback:logback-core
- Multiple vulnerabilities in IBM DataStax Hyper-Converged Database