Insufficient verification of data authenticity in dnsjava - CVE-2024-25638

 

Insufficient verification of data authenticity in dnsjava - CVE-2024-25638

Published: September 26, 2024


Vulnerability identifier: #VU97732
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-25638
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
dnsjava
Netcool Operations Insight
IBM Watson Knowledge Catalog in Cloud Pak for Data
Oracle Communications Cloud Native Core Network Data Analytics Function
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
IBM Cloud Object Storage Systems
IBM Cloud Pak for Watson AIOps
IBM Application Suite - IBM Asset Data Dictionary Component
User Entity Behavior Analytics
Cognos Dashboards on Cloud Pak for Data
Oracle Communications Converged Application Server
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Policy
openEuler
watsonx.data
dnsjava
dnsjava-javadoc

Detailed vulnerability description

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper response validation when handling DNS queries. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. A remote attacker can bypass DNSSEC restrictions.


How to mitigate CVE-2024-25638

Install updates from vendor's website.

Sources