Incorrect Conversion between Numeric Types in Okio - CVE-2023-3635

 

Incorrect Conversion between Numeric Types in Okio - CVE-2023-3635

Published: September 14, 2023 / Updated: January 22, 2026


Vulnerability identifier: #VU80783
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-3635
CWE-ID: CWE-681
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Okio
Maximo Application Suite - Visual Inspection Component
Event Processing
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
openapi-generator
IBM Event Endpoint Management
webMethods Integration Server
DataPower Operations Dashboard
ObjectScale
IBM Planning Analytics Workspace
IBM Business Automation Manager Open Editions
Maximo Application Suite - IoT Component
Dell Data Protection Central
IBM Operations Analytics Predictive Insights
IBM Watson Knowledge Catalog in Cloud Pak for Data
Jira Service Management Data Center
Jira Service Management Server
Confluence Data Center
Bitbucket Data Center
IBM Maximo Application Suite
Bamboo Server
Jira Software Data Center
IBM Integration Bus
IBM Workload Scheduler
Oracle WebCenter Enterprise Capture
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
IBM Process Mining
IBM Fusion HCI
IBM Cloud Transformation Advisor
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
IBM Observability with Instana
Crowd Server
Oracle Access Manager
Java client for Kubernetes & OpenShift
Wildfly
Confluence Server
Juniper Secure Analytics (JSA)
Fuse
Bitbucket Server
AMQ Streams
JBoss Enterprise Application Platform expansion pack (EAP XP)
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Jira Software Server
Event Streams
IBM App Connect Enterprise
IBM Security Guardium
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Unified Data Repository
watsonx.data

How to mitigate CVE-2023-3635

Install updates from vendor's website.

Okio - update to 3.4.0
Event Processing - update to 1.0.4
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
Jira Service Management Data Center - addressed in versions 4.20.28, 5.4.12, 10.3.19, 11.3.2
Jira Service Management Server - addressed in versions 4.20.28, 5.4.12
Crowd Server - addressed in versions 5.0.8, 5.1.6, 5.2.1
Java client for Kubernetes & OpenShift - update to 6.10.0
Wildfly - update to 30.0.0
openapi-generator - update to 7.5.0
Confluence Data Center - addressed in versions 7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2, 8.7.1
Confluence Server - addressed in versions 7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Fuse - update to 7.12.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.5
Bitbucket Data Center - addressed in versions 7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2
Bitbucket Server - addressed in versions 7.21.18, 8.9.7, 8.11.6, 8.12.4, 8.13.3, 8.14.2
IBM Maximo Application Suite - update to 8.10.5
Bamboo Server - addressed in versions 9.2.7, 9.3.5
Jira Software Server - update to 9.4.13
Jira Software Data Center - addressed in versions 9.4.13, 9.12.24, 10.3.19, 11.3.2
IBM Integration Bus - update to 10.1.0.2
IBM Workload Scheduler - update to 10.2.0.1
IBM Event Endpoint Management - update to 11.0.4
webMethods Integration Server - update to 11.1 Fix 1
DataPower Operations Dashboard - update to 1.0.20.1
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.11
IBM Process Mining - update to 1.14.2
watsonx.data - update to 2.0.3
IBM Planning Analytics Workspace - update to 2.0.93
AMQ Streams - update to 2.5.0
IBM Fusion HCI - update to 2.7.1
IBM Cloud Transformation Advisor - update to 3.6.2
JBoss Enterprise Application Platform expansion pack (EAP XP) - update to 4.0.2.GA
QRadar User Behavior Analytics - update to 4.1.16
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.3
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.1
IBM Business Automation Manager Open Editions - update to 8.0.5
Maximo Application Suite - IoT Component - addressed in versions 8.7.15, 8.8.11, 9.0.1
Event Streams - update to 11.4.0
Dell Data Protection Central - update to 19.10.0-4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
IBM Automation Decision Services - update to 23.0.2.0.5
IBM Observability with Instana - update to 268

External References

Related Security Bulletins