Resource exhaustion in es5-ext - CVE-2024-27088

 

Resource exhaustion in es5-ext - CVE-2024-27088

Published: April 10, 2024


Vulnerability identifier: #VU88394
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27088
CWE-ID: CWE-400
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A local privileged user can pass functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` and perform a denial of service (DoS) attack.


Affected software

es5-ext
Storage Defender - Resiliency Service
Cloud Pak for Network Automation
Business Automation Insights
Security QRadar EDR
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Use Case Manager App
IBM Cloud Pak for Business Automation
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Observability with Instana
QRadar Suite
Planning Analytics Local
QRadar Pulse App

How to mitigate CVE-2024-27088

Install updates from vendor's website.

es5-ext - update to 0.10.63
Use Case Manager App - update to 3.10.0
QRadar Suite - update to 1.10.21.0
Storage Defender - Resiliency Service - update to 2.0.3
Cloud Pak for Network Automation - update to 2.7.2
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
Planning Analytics Local - addressed in versions 2.0.0.96, 2.1.3
QRadar Pulse App - update to 2.2.14
Security QRadar EDR - update to 3.12.8
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.1
App Connect Enterprise Certified Container - addressed in versions 5.0.16, 11.4.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
IBM Observability with Instana - update to 271

External References

Related Security Bulletins