Server-Side Request Forgery (SSRF) in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - CVE-2024-22329

 

Server-Side Request Forgery (SSRF) in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - CVE-2024-22329

Published: April 18, 2024


Vulnerability identifier: #VU88803
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2024-22329
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

IBM WebSphere Application Server
IBM WebSphere Application Server Liberty
IBM Tivoli System Automation Application Manager
IBM Transformation Extender Advanced
IBM Rational ClearCase
Engineering Workflow Management
Log Analysis
IBM Operations Analytics Predictive Insights
IBM Intelligent Operations Center
IBM MQ Operator
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM SPSS Analytic Server
IBM Sterling B2B Integrator
IBM Tivoli Netcool Impact
IBM Spectrum Symphony
IBM Maximo Asset Management
WebSphere Remote Server
WebSphere Service Registry and Repository
IBM Rational ClearQuest
CICS Transaction Gateway
IBM Security Verify Governance
InfoSphere Master Data Management
Jazz for Service Management
IBM Cloud Application Business Insights
IBM Process Mining
IBM Cloud Transformation Advisor
IBM Match 360
IBM Spectrum Control
IBM Elastic Storage System
IBM Tivoli Monitoring
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM Common Licensing
IBM TXSeries for Multiplatforms
IBM MQ
IBM Security Verify Governance - Containerized Identity Manager
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Jazz Foundation
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Engineering Requirements Management DOORS Next
Engineering Test Management
Intelligent Operations Center for Emergency Management
Tivoli Composite Application Manager for Application Diagnostics
IBM OpenPages with Watson
Business Monitor
PowerVM NovaLink
IBM Planning Analytics Workspace
Answer Retrieval for Watson Discovery On Prem
IBM Watson Machine Learning Accelerator
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect Operations Center
Storage Protect for Space Management
Maximo Application Suite - Predict Component
IBM MQ Appliance
IBM Workload Automation
Robotic Process Automation for Cloud Pak
Business Automation Insights
IBM i
IBM Tivoli Application Dependency Discovery Manager
IBM Cognos Controller
Financial Transaction Manager
IBM License Metric Tool
Voice Gateway
Planning Analytics Local
IBM Cognos Analytics
IBM Cloud Pak System
IBM Storage Scale System
IBM Watson Explorer Analytical Components
IBM Watson Explorer Foundational Components
IBM InfoSphere Information Server

How to mitigate CVE-2024-22329

Install updates from vendor's website.

IBM WebSphere Application Server - addressed in versions 8.5.5.26, 9.0.5.20
IBM WebSphere Application Server Liberty - update to 24.0.0.5
IBM MQ Operator - addressed in versions 9.3.0.20-r1, 9.4.0.0-r2
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM Tivoli Netcool Impact - update to 7.1.0.34
IBM Spectrum Symphony - update to 7.3.2 FP3
IBM Cognos Controller - update to 11.0.1.0.3
Voice Gateway - addressed in versions 1.0.8.12, 1.0.8.15
Jazz for Service Management - update to 1.1.3.21
IBM Cloud Application Business Insights - addressed in versions 1.1.7.10, 1.1.8.5
IBM Process Mining - update to 1.15.0 IF004
PowerVM NovaLink - addressed in versions 2.0.3.1-240625, 2.1.1-240625, 2.2.1-240626
Planning Analytics Local - update to 2.0.9.20
IBM Planning Analytics Workspace - update to 2.1.4
IBM Cloud Pak System - addressed in versions 2.3.4.1, 24.0.0.6
Answer Retrieval for Watson Discovery On Prem - update to 2.17.0
IBM Cloud Transformation Advisor - update to 3.10.0
Financial Transaction Manager - update to 4.0.6.0 iFix4
IBM Watson Machine Learning Accelerator - update to 5.0.1
IBM Match 360 - update to 5.0.1
IBM Storage Scale System - addressed in versions 5.1.9.5, 5.2.1.0
IBM Spectrum Control - update to 5.4.12
IBM Elastic Storage System - update to 6.1.9.4
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
Storage Protect Client - update to 8.1.23.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.23.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.23.0
Storage Protect Operations Center - update to 8.1.23
Storage Protect for Space Management - update to 8.1.23.0
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.14
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.15, 8.7.9
IBM Maximo Application Suite - addressed in versions 8.10.14, 8.11.11, 9.0.0
Maximo Application Suite - Predict Component - update to 9.0.0
IBM Common Licensing - update to 9.0.0.1
IBM TXSeries for Multiplatforms - update to 9.1.0.3
IBM MQ - addressed in versions 9.1.0.22, 9.2.0.26, 9.3.0.20, 9.4
IBM License Metric Tool - update to 9.2.36
IBM MQ Appliance - addressed in versions 9.3.0.20, 9.3.5.2
IBM Security Verify Governance - Containerized Identity Manager - update to 10.0.2
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix26, 11.1.0.0 ifix19
IBM Workload Automation - addressed in versions 10.1.0.5, 10.2.3
IBM Watson Explorer Analytical Components - addressed in versions 11.0.2.19, 12.0.3.15
IBM Watson Explorer Foundational Components - addressed in versions 11.0.2.19, 12.0.3.15
IBM CICS TX Standard - update to 11.1.0.0 ifix19
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
IBM Business Automation Workflow - addressed in versions 21.0.3 IF033, 23.0.2 IF005
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.16
Business Automation Insights - update to 23.0.2.0.6

External References

Related Security Bulletins