Resource exhaustion in XNIO - CVE-2023-5685

 

Resource exhaustion in XNIO - CVE-2023-5685

Published: June 24, 2024


Vulnerability identifier: #VU93103
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5685
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in NotifierState, when the chain of notifier states becomes problematically large. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

XNIO
Splunk Add-on for JBoss
IBM Watson Knowledge Catalog in Cloud Pak for Data
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
Undertow
JBoss Enterprise Application Platform
IBM Business Automation Manager Open Editions
IBM Cloud Pak for Watson AIOps
Telco Service Activator
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Policy
eap7-jboss-annotations (Red Hat package)
eap7-log4j-jboss-logmanager (Red Hat package)
eap7-h2database (Red Hat package)
eap7-jboss-server-migration (Red Hat package)
eap7-avro (Red Hat package)
eap7-bouncycastle (Red Hat package)
eap7-jboss-marshalling (Red Hat package)
eap7-xml-security (Red Hat package)
eap7-wss4j (Red Hat package)
eap7-xalan-j2 (Red Hat package)
eap7-jackson-databind (Red Hat package)
eap7-apache-cxf (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
eap7-wildfly (Red Hat package)
Red Hat Camel for Spring Boot
IBM InfoSphere Information Server

How to mitigate CVE-2023-5685

Install updates from vendor's website.

XNIO - update to 3.8.16
Splunk Add-on for JBoss - update to 3.1.1
Undertow - addressed in versions 2.2.33, 2.3.14
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
JBoss Enterprise Application Platform - addressed in versions 7.1.8, 7.3.11
IBM Business Automation Manager Open Editions - update to 8.0.7
eap7-jboss-annotations (Red Hat package) - update to api_1.3_spec-2.0.1-4.Final_redhat_00001.1.el7eap
eap7-log4j-jboss-logmanager (Red Hat package) - update to 1.2.2-2.Final_redhat_00002.1.el7eap
eap7-h2database (Red Hat package) - addressed in versions 1.4.197-2.redhat_00005.1.ep7.el7, 1.4.197-3.redhat_00004.1.el7eap
eap7-jboss-server-migration (Red Hat package) - update to 1.7.2-12.Final_redhat_00013.1.el7eap
eap7-avro (Red Hat package) - addressed in versions 1.7.6-2.redhat_00003.1.ep7.el7, 1.7.6-8.redhat_00003.1.el7eap
eap7-bouncycastle (Red Hat package) - update to 1.68.0-1.redhat_00005.1.ep7.el7
eap7-jboss-marshalling (Red Hat package) - addressed in versions 2.0.15-1.Final_redhat_00001.1.el7eap, 2.0.15-1.Final_redhat_00001.1.ep7.el7
eap7-xml-security (Red Hat package) - update to 2.2.3-2.redhat_00001.1.el7eap
eap7-wss4j (Red Hat package) - update to 2.3.3-2.redhat_00001.1.el7eap
eap7-xalan-j2 (Red Hat package) - addressed in versions 2.7.1-26.redhat_00015.1.ep7.el7, 2.7.1-38.redhat_00015.1.el7eap
eap7-jackson-databind (Red Hat package) - update to 2.8.11.6-1.SP1_redhat_00001.1.ep7.el7
eap7-apache-cxf (Red Hat package) - addressed in versions 3.1.16-3.SP1_redhat_00001.1.ep7.el7, 3.4.10-1.SP1_redhat_00001.1.el7eap
eap7-jboss-xnio-base (Red Hat package) - addressed in versions 3.5.10-1.Final_redhat_00001.1.ep7.el7, 3.7.13-1.Final_redhat_00001.1.el7eap
Red Hat Camel for Spring Boot - update to 4.4.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
eap7-wildfly (Red Hat package) - addressed in versions 7.1.8-2.GA_redhat_00002.1.ep7.el7, 7.3.11-4.GA_redhat_00002.1.el7eap
Telco Service Activator - update to 10.1.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5

External References

Related Security Bulletins