Server-Side Request Forgery (SSRF) in IP - CVE-2023-42282
Published: March 1, 2024 / Updated: November 19, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input within the isPublic() function. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
IBM Cloud Pak for Security
IBM Fusion HCI
Unified OSS Console Assurance Monitoring (UOCAM)
Red Hat OpenShift Dev Spaces
IBM Watson Assistant for IBM Cloud Pak for Data
Confluence Data Center
IBM Maximo Application Suite
Bitbucket Data Center
IBM Cloud Pak for Business Automation
IBM Observability with Instana
Software Support App (iOS)
Software Support app (Android)
watsonx Orchestrate Developer Edition
Cloud Pak for Network Automation
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
IBM Planning Analytics Workspace
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Dell Policy Manager for Secure Connect Gateway (SCG)
Maximo Application Suite - IoT Component
Maximo Application Suite - Monitor Component
Storage Protect Plus Server
QRadar Suite
IBM Security QRadar Analyst Workflow
Ubuntu
node-ip (Ubuntu package)
Network Observability plugin for the Openshift Console
IBM Cloud Pak System
Cloud Pak for Data
IBM DB2
IBM Storage Scale System
Confluence Server
Bitbucket Server
IBM App Connect Enterprise
IBM Cognos Analytics
How to mitigate CVE-2023-42282
Software Support App (iOS) - update to 2.0.0
Software Support app (Android) - update to 2.0.0
watsonx Orchestrate Developer Edition - update to 1.15.0
QRadar Suite - update to 1.10.19.0
Cloud Pak for Network Automation - update to 2.7.2
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.2
node-ip (Ubuntu package) - addressed in versions Ubuntu Pro, 2.0.0+~1.1.0-1ubuntu0.1
Cognos Analytics Mobile (iOS) - update to 1.1.20
Cognos Analytics Mobile (Android) - update to 1.1.20
Network Observability plugin for the Openshift Console - update to 1.6.0
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
IBM Fusion HCI - update to 2.8.0
IBM Security QRadar Analyst Workflow - update to 2.32.1
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.4
Red Hat OpenShift Dev Spaces - update to 3.17.0
Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.8
DB2 Warehouse on Cloud Pak for Data - update to 4.8.8
IBM DB2 - update to 5.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0
IBM Storage Scale System - addressed in versions 5.1.9.3, 5.2.0.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
Confluence Data Center - addressed in versions 8.5.18, 9.2.1, 9.3.1, 9.5.4, 10.0.2, 10.1.0
Confluence Server - addressed in versions 8.5.18, 9.2.1, 9.3.1, 9.5.4, 10.0.2, 10.1.0
Maximo Application Suite - IoT Component - addressed in versions 8.7.14, 8.8.11, 9.0.1
Maximo Application Suite - Monitor Component - addressed in versions 8.10.8, 8.11.5
IBM Maximo Application Suite - addressed in versions 8.10.16, 8.11.13, 9.0.1
Bitbucket Data Center - update to 8.19.25
Bitbucket Server - update to 8.19.25
Storage Protect Plus Server - update to 10.1.16.2
IBM App Connect Enterprise - addressed in versions 11.0.0.25, 12.0.11.2
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.31, 23.0.2.3
IBM Observability with Instana - update to 268
External References
Related Security Bulletins
- SSRF in Fedor Indutny IP address tools for node.js
- Ubuntu update for node-ip
- Server-side request forgery in IBM Cloud Pak System
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Observability with Instana
- Server-side request forgery in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Server-side request forgery in IBM Maximo Application Suite - Monitor Component
- Multiple vulnerabilities in IBM Analyst Workflow
- Server-side request forgery in IBM Storage Scale
- Multiple vulnerabilities in IBM Planning Analytics Local - IBM Planning Analytics Workspace
- Server-side request forgery in IBM Storage Fusion HCI
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in Dell Secure Connect Gateway Policy Manager
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console 1.6
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data
- Server-Side Request Forgery (SSRF) in IBM Cloud Pak for Data
- Server-side request forgery in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in Storage Protect Plus Server
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (Android)
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (iOS)
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- IBM Maximo Application Suite and IBM Maximo Application Suite - Iot Component update for Node.js IP package
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Software Support app
- Multiple vulnerabilities in HPE Unified OSS Console Assurance Monitoring (UOCAM)
- Multiple vulnerabilities in IBM watsonx Orchestrate with watsonx Assistant Cartridge
- Confluence Data Center and Server update for indutny IP
- Bitbucket Data Center and Server update for Indutny IP
- Multiple vulnerabilities in IBM watsonx Orchestrate Developer Edition