Insufficient verification of data authenticity in dnsjava - CVE-2024-25638

 

Insufficient verification of data authenticity in dnsjava - CVE-2024-25638

Published: September 26, 2024


Vulnerability identifier: #VU97732
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-25638
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper response validation when handling DNS queries. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. A remote attacker can bypass DNSSEC restrictions.


Affected software

dnsjava
Netcool Operations Insight
IBM Watson Knowledge Catalog in Cloud Pak for Data
Oracle Communications Cloud Native Core Network Data Analytics Function
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
IBM Cloud Object Storage Systems
IBM Cloud Pak for Watson AIOps
IBM Application Suite - IBM Asset Data Dictionary Component
User Entity Behavior Analytics
Cognos Dashboards on Cloud Pak for Data
Oracle Communications Converged Application Server
IBM InfoSphere Information Server
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
openEuler
watsonx.data
dnsjava
dnsjava-javadoc

How to mitigate CVE-2024-25638

Install updates from vendor's website.

dnsjava - update to 3.6.0
Netcool Operations Insight - update to 1.6.15
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.15
watsonx.data - update to 2.0.3
dnsjava - update to 3.5.3-2
dnsjava-javadoc - update to 3.5.3-2
IBM Cloud Object Storage Systems - addressed in versions 3.18.0.84, 3.18.5.40
User Entity Behavior Analytics - update to 5.0.2
Cognos Dashboards on Cloud Pak for Data - update to 5.1

External References

Related Security Bulletins