Out-of-bounds read in OpenJ9 - CVE-2023-2597

 

Out-of-bounds read in OpenJ9 - CVE-2023-2597

Published: June 5, 2023


Vulnerability identifier: #VU76906
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2597
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a string is not properly checked against the size of the buffer. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system.


Affected software

OpenJ9
IBM Security Guardium
IBM Integration Bus
IBM Tivoli Business Service Manager
IBM SPSS Collaboration and Deployment Services
IBM Sterling Transformation Extender
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Intelligent Operations Center
Engineering Lifecycle Optimization - Engineering Insights
IBM Rational Build Forge
WebSphere Remote Server
IBM Common Licensing
CICS Transaction Gateway
Rational Service Tester
IBM Security Verify Governance
IBM Cloud Application Business Insights
IBM Sterling Connect:Direct FTP+
IBM Operations Analytics Predictive Insights
IBM Cloud Transformation Advisor
Content Collector for Email
Content Collector for File Systems
Content Collector for Microsoft SharePoint
IBM Tivoli System Automation Application Manager
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Spectrum Control
IBM Sterling Connect:Direct for UNIX
IBM Sterling Connect:Direct Web Services
IBM Sterling Partner Engagement Manager
IBM Elastic Storage System
IBM Sterling Control Center
IBM Tivoli Monitoring
IBM Tivoli Netcool Impact
Netcool/OMNIbus
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM Rational ClearQuest
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
Rational Business Developer (RBD)
Jazz Foundation
IBM Java SDK
IBM CICS TX Advanced
IBM App Connect Enterprise
IBM CICS TX Standard
IBM Engineering Requirements Quality Assistant
Engineering Test Management
IBM Engineering Lifecycle Optimization - Publishing
IBM Engineering Requirements Management DOORS Next
Db2 Big SQL
IBM Security Directory Suite
IBM OpenPages with Watson
InfoSphere Data Architect
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
Rational Performance Tester
IBM Security Verify Bridge for Directory Sync
dashDB Local
B2B Advanced Communications
PowerVM NovaLink
IBM Planning Analytics Workspace
Tivoli System Automation for Multiplatforms
IBM Sterling Connect:Direct for Microsoft Windows
IBM Security Directory Server
Security Directory Integrator
IBM Semeru Runtimes
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect Server
IBM Workload Automation
Cognos Transformer
Robotic Process Automation for Cloud Pak
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
IBM i
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Legacy Module
SUSE Package Hub 15
openSUSE Leap
IBM Data Risk Manager
IBM Tivoli Application Dependency Discovery Manager
Sterling Connect:Direct Browser User Interface
IBM Cloud Pak for Multicloud Management
IBM Tivoli Network Manager (ITNM)
IBM App Connect Professional
IBM Sterling Connect:Direct File Agent
IBM Qradar SIEM
IBM Cognos Controller
IBM License Metric Tool
Event Streams
java-1_8_0-ibm
java-1_8_0-ibm-alsa
java-1_8_0-ibm-plugin
java-1_8_0-ibm-devel
java-1_8_0-ibm-devel-32bit
java-1_8_0-ibm-demo
java-1_8_0-ibm-src
java-1_8_0-ibm-32bit
java-1_8_0-openj9
java-1_8_0-openj9-demo
java-1_8_0-openj9-debugsource
java-1_8_0-openj9-demo-debuginfo
java-1_8_0-openj9-devel-debuginfo
java-1_8_0-openj9-debuginfo
java-1_8_0-openj9-headless
java-1_8_0-openj9-devel
java-1_8_0-openj9-headless-debuginfo
java-1_8_0-openj9-src
java-1_8_0-openj9-javadoc
java-1_8_0-openj9-accessibility
Planning Analytics Local
Operational Decision Manager
IBM Cognos Analytics
IBM Cloud Pak System
Liberty for Java for IBM Cloud
IBM Storage Scale System
IBM FileNet Content Manager
IBM DB2
IBM Security SOAR

How to mitigate CVE-2023-2597

Install updates from vendor's website.

OpenJ9 - update to 0.38.0
IBM Data Risk Manager - update to 2.0.6.18
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
IBM Intelligent Operations Center - update to 5.2.4
Db2 Big SQL - update to 7.6
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
IBM Rational Build Forge - update to 8.0.0.24
InfoSphere Data Architect - update to 9.2.1
IBM Cognos Controller - update to 11.0.1.0.3
dashDB Local - update to 11.5.9.0
B2B Advanced Communications - update to 1.0.0.10
IBM Cloud Application Business Insights - update to 1.1.8.2
IBM Sterling Connect:Direct FTP+ - update to 1.3.0.0.24
IBM Operations Analytics Predictive Insights - update to 1.3.6.6
IBM Sterling Connect:Direct File Agent - update to 1.4.0.2.42
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-36
java-1_8_0-ibm - addressed in versions 1.8.0_sr8.5-30.108.1, 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr8.5-30.108.1, 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr8.5-30.108.1, 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr8.5-30.108.1, 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-devel-32bit - update to 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-demo - update to 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-src - update to 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-ibm-32bit - update to 1.8.0_sr8.5-150000.3.74.1
java-1_8_0-openj9 - update to 1.8.0.372-150200.3.33.2
java-1_8_0-openj9-demo - update to 1.8.0.372-150200.3.33.2
java-1_8_0-openj9-debugsource - update to 1.8.0.372-150200.3.33.2
java-1_8_0-openj9-demo-debuginfo - update to 1.8.0.372-150200.3.33.2
java-1_8_0-openj9-devel-debuginfo - update to 1.8.0.372-150200.3.33.2
java-1_8_0-openj9-debuginfo - update to 1.8.0.372-150200.3.33.2
java-1_8_0-openj9-headless - update to 1.8.0.372-150200.3.33.2
java-1_8_0-openj9-devel - update to 1.8.0.372-150200.3.33.2
java-1_8_0-openj9-headless-debuginfo - update to 1.8.0.372-150200.3.33.2
java-1_8_0-openj9-src - update to 1.8.0.372-150200.3.33.2
java-1_8_0-openj9-javadoc - update to 1.8.0.372-150200.3.33.2
java-1_8_0-openj9-accessibility - update to 1.8.0.372-150200.3.33.2
PowerVM NovaLink - addressed in versions 2.0.3.1.1-230726, 2.1.1-230725
Planning Analytics Local - update to 2.0.9.19
IBM Planning Analytics Workspace - update to 2.0.91
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
IBM Cloud Transformation Advisor - update to 3.6.2
Content Collector for Email - update to 4.0.1.15 IF006
Content Collector for File Systems - update to 4.0.1.15 IF006
Content Collector for Microsoft SharePoint - update to 4.0.1.15 IF006
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.2.0.15, 4.1.0.3.0.11, 4.1.0.4.0.8, 4.1.0.5.0.6
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.4.0.19, 4.1.0.5.0.13, 4.1.0.6.0.8, 4.1.0.7.0.6, 4.1.1.0.0.2
Liberty for Java for IBM Cloud - update to 4.2-20230619-0514
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.1
IBM Decision Optimization for Cloud Pak for Data - update to 4.7.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Storage Scale System - addressed in versions 5.1.2.13, 5.1.8.2
IBM Spectrum Control - update to 5.4.10.2
IBM FileNet Content Manager - addressed in versions 5.5.8.0 IF005, 5.5.9.0 IF003
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.0.0.2.152, 6.1.0.4.88, 6.2.0.6.24, 6.3.0.0.11
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.0.0.4.68, 6.1.0.2.64, 6.2.0.4.39, 6.3.0.0.7
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.19, 6.2.0.17
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.8, 6.2.0.6, 6.2.1.3, 6.2.2.1
IBM Elastic Storage System - addressed in versions 6.1.2.8, 6.1.9.0
IBM Sterling Control Center - addressed in versions 6.2.1.0.13, 6.3.1.0.2
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Security Directory Server - update to 6.4.0.28
IBM Tivoli Netcool Impact - update to 7.1.0.31
Security Directory Integrator - update to 7.2.0.10
IBM Java SDK - update to 8.0-8.5
IBM Semeru Runtimes - addressed in versions 8.0.372.0, 11.0.19.0, 17.0.7.0
Netcool/OMNIbus - update to 8.1.0.31
IBM Cloud Application Performance Management (APM) - addressed in versions 8.1.4.0.12, 8.1.4.0.14
Storage Protect Client - update to 8.1.20.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.20.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.20.0
Storage Protect for Space Management - update to 8.1.20.0
Storage Protect Server - update to 8.1.21
IBM TXSeries for Multiplatforms - addressed in versions 8.2.0.2, 9.1.0.2
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 38, 8.11.0.1 Interim fix 20, 8.11.1 Interim fix 8
IBM Rational ClearQuest - update to 9.0.2.8
IBM License Metric Tool - update to 9.2.32
IBM Workload Automation - addressed in versions 9.5.0.7, 10.1.0.4
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix19, 11.1.0.0 ifix11
IBM App Connect Enterprise - addressed in versions 11.0.0.21, 12.0.9.0
IBM CICS TX Standard - update to 11.1.0.0 ifix11
IBM DB2 - addressed in versions 11.1.4.7, 11.5.7, 11.5.8
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
Cognos Transformer - update to 11.1.7 Fix Pack 8
Event Streams - update to 11.2.1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF023, 23.0.1 IF001
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.23, 23.0.1.1
IBM Robotic Process Automation - addressed in versions 21.0.7.8, 23.0.9
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.8, 23.0.9
IBM Security SOAR - update to 49.1

External References

Related Security Bulletins