Input validation error in Apache CXF - CVE-2024-32007

 

Input validation error in Apache CXF - CVE-2024-32007

Published: September 18, 2024


Vulnerability identifier: #VU97458
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-32007
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists within the JOSE code due to insufficient validation of user-supplied input passed via the p2c parameter. A remote attacker can pass a large value for the affected parameter in a token and perform a denial of service (DoS) attack.


Affected software

Apache CXF
IBM Tivoli Application Dependency Discovery Manager
Oracle Banking Cash Management
Oracle Banking Supply Chain Finance
Oracle Banking Liquidity Management
Oracle Business Intelligence Enterprise Edition
NetWorker Management Console (NMC)
Bitbucket Data Center
IBM Sterling B2B Integrator
EMC NetWorker Server
IBM Cloud Pak for Business Automation
Bitbucket Server
Red Hat Camel for Spring Boot
Juniper Secure Analytics (JSA)

How to mitigate CVE-2024-32007

Install updates from vendor's website.

Apache CXF - addressed in versions 3.5.9, 3.6.4, 4.0.5
Bitbucket Data Center - addressed in versions 8.9.19, 8.19.9
Bitbucket Server - addressed in versions 8.9.19, 8.19.9
Red Hat Camel for Spring Boot - addressed in versions 3.20.7, 4.4.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.4
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
NetWorker Management Console (NMC) - update to 19.10.0.5
EMC NetWorker Server - update to 19.10.0.5
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001

External References

Related Security Bulletins