Resource exhaustion in IBM Java SDK - CVE-2023-38264

 

Resource exhaustion in IBM Java SDK - CVE-2023-38264

Published: May 10, 2024


Vulnerability identifier: #VU89343
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38264
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

IBM Java SDK
Rational Business Developer (RBD)
IBM App Connect Enterprise
IBM CICS TX Advanced
IBM CICS TX Standard
WebSphere Service Registry and Repository
IBM Tivoli Business Service Manager
IBM Tivoli Netcool Impact
IBM Spectrum Symphony
IBM Maximo Asset Management
IBM Security Access Manager for Enterprise Single-Sign On
IBM Sterling Transformation Extender
IBM Business Automation Workflow
Financial Transaction Manager for Corporate Payment Services (CPS)
Financial Transaction Manager for Digital Payments (DP)
IBM Cloud Transformation Advisor
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Sterling Secure Proxy
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
IBM Tivoli Monitoring
IBM Rational Build Forge
Netcool/OMNIbus
IBM Cloud Application Performance Management (APM)
WebSphere eXtreme Scale
IBM Common Licensing
IBM TXSeries for Multiplatforms
IBM Security Verify Governance - Containerized Identity Manager
IBM Security Verify Governance
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
IBM AIX
IBM i
Red Hat Enterprise Linux for x86_64
IBM VIOS
IBM WebSphere Application Server
Tivoli Network Manager IP Edition
Rational Synergy
Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines
Tivoli Monitoring for Virtual Environments Base
IBM OpenPages with Watson
CICS Transaction Gateway for Multiplatforms
DB2 Query Management Facility for z/OS
IBM Planning Analytics Workspace
Financial Transaction Manager for High Value Payments
IBM Secure External Authentication Server
Tivoli Network Configuration Manager IP Edition
DevOps
Security Directory Integrator
Db2 Big SQL
Storage Protect Backup-Archive Client
Storage Protect Operations Center
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect Server
Storage Protect for Virtual Environments: Data Protection for VMware
Integration Bus for z/OS
Cognos Transformer
Robotic Process Automation for Cloud Pak
Storage Insights - Data Collector
IBM Qradar SIEM
IBM Cognos Controller
Financial Transaction Manager
Event Streams
Juniper Secure Analytics (JSA)
IBM Security SOAR
IBM InfoSphere Information Server
Voice Gateway
java-1_8_0-ibm
java-1_8_0-ibm-devel
java-1_8_0-ibm-alsa
java-1_8_0-ibm-plugin
java-1.8.0-ibm-demo (Red Hat package)
java-1.8.0-ibm-webstart (Red Hat package)
java-1.8.0-ibm-src (Red Hat package)
java-1.8.0-ibm-plugin (Red Hat package)
java-1.8.0-ibm-jdbc (Red Hat package)
java-1.8.0-ibm-headless (Red Hat package)
java-1.8.0-ibm-devel (Red Hat package)
java-1.8.0-ibm (Red Hat package)
Planning Analytics Local
IBM Cloud Pak System
IBM Tivoli Application Dependency Discovery Manager
IBM App Connect Professional
IBM Watson Explorer Deep Analytics Edition Analytical Components
IBM Security Guardium

How to mitigate CVE-2023-38264

Install updates from vendor's website.

IBM Java SDK - addressed in versions 7.1.5.22, 8.0.8.25
Tivoli Network Manager IP Edition - update to 4.2.0.20
IBM Tivoli Netcool Impact - update to 7.1.0.34
Rational Synergy - update to 7.2.2.7
Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines - update to 7.2.10
IBM Spectrum Symphony - update to 7.3.2 FP3
Tivoli Monitoring for Virtual Environments Base - update to 7.3.7
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Cognos Controller - update to 11.0.1.0.3
IBM App Connect Enterprise - update to 12.0.12.3
Voice Gateway - addressed in versions 1.0.8.13, 1.0.8.16
java-1_8_0-ibm - update to 1.8.0_sr8.25-30.123.1
java-1_8_0-ibm-devel - update to 1.8.0_sr8.25-30.123.1
java-1_8_0-ibm-alsa - update to 1.8.0_sr8.25-30.123.1
java-1_8_0-ibm-plugin - update to 1.8.0_sr8.25-30.123.1
java-1.8.0-ibm-demo (Red Hat package) - addressed in versions 1.8.0.8.25-1.el8_10, 1.8.0.8.25-1jpp.1.el7, 1.8.0.8.30-2.el8_10
java-1.8.0-ibm-webstart (Red Hat package) - addressed in versions 1.8.0.8.25-1.el8_10, 1.8.0.8.30-2.el8_10
java-1.8.0-ibm-src (Red Hat package) - addressed in versions 1.8.0.8.25-1.el8_10, 1.8.0.8.25-1jpp.1.el7, 1.8.0.8.30-2.el8_10
java-1.8.0-ibm-plugin (Red Hat package) - addressed in versions 1.8.0.8.25-1.el8_10, 1.8.0.8.25-1jpp.1.el7, 1.8.0.8.30-2.el8_10
java-1.8.0-ibm-jdbc (Red Hat package) - addressed in versions 1.8.0.8.25-1.el8_10, 1.8.0.8.25-1jpp.1.el7, 1.8.0.8.30-2.el8_10
java-1.8.0-ibm-headless (Red Hat package) - addressed in versions 1.8.0.8.25-1.el8_10, 1.8.0.8.30-2.el8_10
java-1.8.0-ibm-devel (Red Hat package) - addressed in versions 1.8.0.8.25-1.el8_10, 1.8.0.8.25-1jpp.1.el7, 1.8.0.8.30-2.el8_10
java-1.8.0-ibm (Red Hat package) - addressed in versions 1.8.0.8.25-1.el8_10, 1.8.0.8.25-1jpp.1.el7, 1.8.0.8.30-2.el8_10
Planning Analytics Local - update to 2.0.9.20
IBM Planning Analytics Workspace - update to 2.1.4
IBM Cloud Pak System - update to 2.3.4.1
Financial Transaction Manager for Corporate Payment Services (CPS) - update to 3.2.13
Financial Transaction Manager for High Value Payments - update to 3.2.13
Financial Transaction Manager for Digital Payments (DP) - update to 3.2.13
IBM Cloud Transformation Advisor - update to 3.10.1
Financial Transaction Manager - update to 4.0.6.0 iFix4
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.0
IBM Spectrum Control - update to 5.4.13
IBM Sterling Secure Proxy - addressed in versions 6.0.3.1, 6.1.0.1
IBM Secure External Authentication Server - addressed in versions 6.0.3.1, 6.1.0.2
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.25, 6.2.0.24, 6.3.0.9
IBM Sterling Control Center - addressed in versions 6.2.1.0.14, 6.3.1.0.3
IBM Tivoli Monitoring - update to 6.3.0 FP7 Service Pack 6
Tivoli Network Configuration Manager IP Edition - update to 6.4.2.21
DevOps - update to 7.0.0.2
Security Directory Integrator - addressed in versions 7.2.0 LA0032, 10.0.0 LA0002
IBM Tivoli Application Dependency Discovery Manager - update to 7.3.0.11
IBM App Connect Professional - update to 7.5.5.0.26
Db2 Big SQL - update to 7.7
IBM Rational Build Forge - update to 8.0.0.27
Netcool/OMNIbus - update to 8.1.0.33
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
Storage Protect Backup-Archive Client - update to 8.1.24
Storage Protect Operations Center - update to 8.1.24
Storage Protect for Space Management - update to 8.1.24.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.24.0
Storage Protect Server - update to 8.1.24
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.24.0
IBM WebSphere Application Server - update to 8.5.5.26
WebSphere eXtreme Scale - update to 8.6.1.6 PH62624 iFix
IBM Common Licensing - update to 9.0.0.1
IBM TXSeries for Multiplatforms - update to 9.1.0.3
IBM Security Verify Governance - Containerized Identity Manager - update to 10.0.2
IBM Security Verify Governance - update to 10.0.2.0.3
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix30, 11.1.0.0 ifix22
Integration Bus for z/OS - update to 10.1.0.3
IBM CICS TX Standard - update to 11.1.0.0 ifix23
Cognos Transformer - addressed in versions 11.2.4 FP5, 12.0.4
Event Streams - update to 11.4.0
IBM Security Guardium - update to 12.0p30
IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.16
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18
IBM Security SOAR - update to 51.0.2.2
Storage Insights - Data Collector - update to 20241009-0649

External References

Related Security Bulletins