Resource exhaustion in Bouncy Castle for Java - CVE-2023-33202

 

Resource exhaustion in Bouncy Castle for Java - CVE-2023-33202

Published: January 29, 2024


Vulnerability identifier: #VU85874
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-33202
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when parsing OpenSSL PEM encoded streams containing X.509 certificates. A remote attacker can send ASN.1 data through the PEMParser to trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Bouncy Castle for Java
Amazon Linux AMI
DataPower Operations Dashboard
Oracle Business Intelligence Enterprise Edition
webMethods Managed File Transfer
ApplinX
IBM Application Suite - IBM Asset Data Dictionary Component
Storage Copy Data Management
Cloud Pak for Network Automation
PowerStore T
Dell Policy Manager for Secure Connect Gateway (SCG)
Maximo Application Suite - IoT Component
Log Analysis
Splunk AppDynamics Database Agent
App Connect Enterprise Certified Container
IBM Maximo Application Suite
IBM Observability with Instana
Oracle Analytics Desktop
IBM Disconnected Log Collector
bouncycastle
IBM Data Risk Manager
AMQ Streams
IBM InfoSphere Information Server

How to mitigate CVE-2023-33202

Install updates from vendor's website.

Bouncy Castle for Java - update to 1.73
DataPower Operations Dashboard - update to 1.0.20.1
Log Analysis - update to 1.3.8
Splunk AppDynamics Database Agent - update to 26.1.0
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.6
IBM Disconnected Log Collector - update to 1.8.6
bouncycastle - update to 1.70-4
IBM Data Risk Manager - update to 2.0.6.20
Storage Copy Data Management - update to 2.2.27.0
AMQ Streams - update to 2.7.0
Cloud Pak for Network Automation - update to 2.7.5
PowerStore T - update to 3.6.1.4-2413340
App Connect Enterprise Certified Container - addressed in versions 5.0.11, 10.0.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
Maximo Application Suite - IoT Component - addressed in versions 8.7.15, 8.8.11, 9.0.1
IBM Maximo Application Suite - addressed in versions 8.10.19, 8.11.16, 9.0.4
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
IBM Observability with Instana - update to 272

External References

Related Security Bulletins