Out-of-bounds write in Apache Commons Configuration - CVE-2024-29131

 

Out-of-bounds write in Apache Commons Configuration - CVE-2024-29131

Published: March 21, 2024 / Updated: January 14, 2025


Vulnerability identifier: #VU87706
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-29131
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input. A remote attacker can pass specialy crafted data to the application, trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

Apache Commons Configuration
Confluence Data Center
IBM Cloud Transformation Advisor
IBM Security Guardium Key Lifecycle Manager (GKLM)
SAP BusinessObjects Business Intelligence suite
WebSphere Remote Server
IBM Security Verify Governance
Oracle Middleware Common Libraries and Tools
Migration Toolkit for Runtimes
Log Analysis
IBM Cloud Object Storage Systems
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Tivoli Business Service Manager
IBM Sterling Control Center
Red Hat Migration Toolkit for Applications
IBM Cloud Application Performance Management (APM)
WebSphere eXtreme Scale
IBM Common Licensing
IBM Cloud Pak for Business Automation
Confluence Server
Guardium Data Security Center (GDSC)
DataStage on Cloud Pak for Data
Oracle Business Intelligence Enterprise Edition
Db2 Big SQL
IBM OpenPages with Watson
Datacap
IBM Application Suite - IBM Asset Data Dictionary Component
Analytics Content Hub
User Entity Behavior Analytics
Cognos Dashboards on Cloud Pak for Data
IBM Sterling Connect:Direct for Microsoft Windows
Storage Protect Server
Oracle Hospitality Cruise Shipboard Property Management System
Fedora
IBM Cloud Pak System
apache-commons-configuration
Jazz Reporting Service
IBM Cognos Command Center
AMQ Broker
IBM DB2

How to mitigate CVE-2024-29131

Install updates from vendor's website.

Apache Commons Configuration - update to 2.10.1
Confluence Data Center - addressed in versions 7.19.23, 8.5.9, 8.9.1
Confluence Server - addressed in versions 7.19.23, 8.5.9, 8.9.1
IBM Cloud Transformation Advisor - update to 3.10.2
Guardium Data Security Center (GDSC) - update to 3.8.5
DataStage on Cloud Pak for Data - update to 5.0.0
Db2 Big SQL - update to 7.6.8
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.15
Migration Toolkit for Runtimes - update to 1.2.6
Log Analysis - update to 1.3.8.0
Analytics Content Hub - update to 2.3
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
apache-commons-configuration - update to 2.10.1-1.fc39
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0
User Entity Behavior Analytics - update to 5.0.2
Cognos Dashboards on Cloud Pak for Data - update to 5.1
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.0.0.4.88, 6.1.0.2.87, 6.2.0.6.20, 6.3.0.3.4
IBM Tivoli Business Service Manager - update to 6.2.0.5.5
IBM Sterling Control Center - addressed in versions 6.2.1.0.14, 6.3.1.0.3
Red Hat Migration Toolkit for Applications - update to 6.2.3
Jazz Reporting Service - addressed in versions 7.0.3 iFix009, 7.02 iFix031
AMQ Broker - update to 7.12.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.4
Storage Protect Server - update to 8.1.24
WebSphere eXtreme Scale - update to 8.6.1.6 PH61029 iFix
IBM Common Licensing - update to 9.0.0.1
IBM Cognos Command Center - update to 10.2.5 IF2
IBM DB2 - addressed in versions 11.1.4.7, 11.5.8, 11.5.9
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001

External References

Related Security Bulletins