Server-Side Request Forgery (SSRF) in IP - CVE-2023-42282

 

Server-Side Request Forgery (SSRF) in IP - CVE-2023-42282

Published: March 1, 2024 / Updated: November 19, 2025


Vulnerability identifier: #VU86944
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2023-42282
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input within the isPublic() function. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

IP
IBM Cloud Pak for Security
IBM Fusion HCI
Unified OSS Console Assurance Monitoring (UOCAM)
Red Hat OpenShift Dev Spaces
IBM Watson Assistant for IBM Cloud Pak for Data
Confluence Data Center
IBM Maximo Application Suite
Bitbucket Data Center
IBM Cloud Pak for Business Automation
IBM Observability with Instana
Software Support App (iOS)
Software Support app (Android)
watsonx Orchestrate Developer Edition
Cloud Pak for Network Automation
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
IBM Planning Analytics Workspace
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Dell Policy Manager for Secure Connect Gateway (SCG)
Maximo Application Suite - IoT Component
Maximo Application Suite - Monitor Component
Storage Protect Plus Server
QRadar Suite
IBM Security QRadar Analyst Workflow
Ubuntu
node-ip (Ubuntu package)
Network Observability plugin for the Openshift Console
IBM Cloud Pak System
Cloud Pak for Data
IBM DB2
IBM Storage Scale System
Confluence Server
Bitbucket Server
IBM App Connect Enterprise
IBM Cognos Analytics

How to mitigate CVE-2023-42282

Install updates from vendor's website.

IP - update to 1.1.9
Software Support App (iOS) - update to 2.0.0
Software Support app (Android) - update to 2.0.0
watsonx Orchestrate Developer Edition - update to 1.15.0
QRadar Suite - update to 1.10.19.0
Cloud Pak for Network Automation - update to 2.7.2
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.2
node-ip (Ubuntu package) - addressed in versions Ubuntu Pro, 2.0.0+~1.1.0-1ubuntu0.1
Cognos Analytics Mobile (iOS) - update to 1.1.20
Cognos Analytics Mobile (Android) - update to 1.1.20
Network Observability plugin for the Openshift Console - update to 1.6.0
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
IBM Fusion HCI - update to 2.8.0
IBM Security QRadar Analyst Workflow - update to 2.32.1
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.4
Red Hat OpenShift Dev Spaces - update to 3.17.0
Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.8
DB2 Warehouse on Cloud Pak for Data - update to 4.8.8
IBM DB2 - update to 5.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0
IBM Storage Scale System - addressed in versions 5.1.9.3, 5.2.0.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
Confluence Data Center - addressed in versions 8.5.18, 9.2.1, 9.3.1, 9.5.4, 10.0.2, 10.1.0
Confluence Server - addressed in versions 8.5.18, 9.2.1, 9.3.1, 9.5.4, 10.0.2, 10.1.0
Maximo Application Suite - IoT Component - addressed in versions 8.7.14, 8.8.11, 9.0.1
Maximo Application Suite - Monitor Component - addressed in versions 8.10.8, 8.11.5
IBM Maximo Application Suite - addressed in versions 8.10.16, 8.11.13, 9.0.1
Bitbucket Data Center - update to 8.19.25
Bitbucket Server - update to 8.19.25
Storage Protect Plus Server - update to 10.1.16.2
IBM App Connect Enterprise - addressed in versions 11.0.0.25, 12.0.11.2
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.31, 23.0.2.3
IBM Observability with Instana - update to 268

External References

Related Security Bulletins