Deserialization of Untrusted Data in Logback - CVE-2023-6378

 

Deserialization of Untrusted Data in Logback - CVE-2023-6378

Published: January 19, 2024


Vulnerability identifier: #VU85618
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-6378
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insecure input validation when processing serialized data in logback receiver component. A remote attacker can pass specially crafted data to the application and cause a denial of service condition on the target system.


Affected software

Logback
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Operations Analytics Predictive Insights
PowerVC
IBM Sterling Partner Engagement Manager
Bitbucket Data Center
IBM Process Mining
Unified OSS Console Assurance Monitoring (UOCAM)
Red Hat OpenShift Dev Spaces
QRadar User Behavior Analytics
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Maximo Asset Management
IBM Maximo Application Suite
IBM Workload Scheduler
PowerProtect Data Manager
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
DataStax Hyper-Converged Database
Cloud Pak for Network Automation
IBM Business Automation Manager Open Editions
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Oxygen XML Editor
Oxygen XML Developer
Oxygen XML Author
IBM Application Suite - IBM Asset Data Dictionary Component
ObjectScale
IBM i Modernization Engine for Lifecycle Integration
IBM Planning Analytics Workspace
Storage Copy Data Management
PowerStore T
Dell EMC PowerStore Family Operating System
Storage Protect Server
Storage Virtualize
watsonx.data
Red Hat Camel for Spring Boot
Bitbucket Server
AMQ Broker
Fuse
Communications Service Catalog and Design
Ubuntu
openEuler
Oracle Hospitality Cruise Shipboard Property Management System
OpenView Performance Manager (OVPM)
logback (Ubuntu package)
logback
logback-access
logback-help
logback-examples
Operational Decision Manager

How to mitigate CVE-2023-6378

Install updates from vendor's website.

Logback - addressed in versions 1.3.14, 1.4.14
DataStax Hyper-Converged Database - update to 1.2.5
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
watsonx.data - update to 2.0.2
Cloud Pak for Network Automation - update to 2.7.2
Red Hat Camel for Spring Boot - update to 4.0.3
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
Bitbucket Server - addressed in versions 7.21.19, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0
Bitbucket Data Center - addressed in versions 7.21.19, 8.9.9, 8.13.5, 8.14.4, 8.15.3, 8.16.2, 8.17.0
IBM Business Automation Manager Open Editions - update to 8.0.7
OpenView Performance Manager (OVPM) - update to T0684V01^ABL
logback (Ubuntu package) - addressed in versions 1:1.1.3-2ubuntu0.1~esm1, 1:1.2.3-2ubuntu1~18.04.1+esm1, 1:1.2.3-5ubuntu0.1~esm1, 1:1.2.10-1ubuntu0.1~esm1
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.6
logback - update to 1.2.8-3
logback-access - update to 1.2.8-3
logback-help - update to 1.2.8-3
logback-examples - update to 1.2.8-3
ObjectScale - update to 1.4.0
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.6
IBM Process Mining - update to 1.14.3
IBM Planning Analytics Workspace - update to 2.0.93
Storage Copy Data Management - update to 2.2.24.1
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.4
PowerStore T - update to 3.6.1.2-2315284
Red Hat OpenShift Dev Spaces - update to 3.15.0
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
QRadar User Behavior Analytics - update to 4.1.16
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
IBM Maximo Asset Management - update to 7.6.1.3.16
AMQ Broker - update to 7.12.0
Fuse - update to 7.13.0
Storage Protect Server - update to 8.1.22
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
IBM Maximo Application Suite - addressed in versions 8.10.7, 8.11.4
IBM Workload Scheduler - addressed in versions 9.5.0.7, 10.1.0.5, 10.2.2
PowerProtect Data Manager - update to 19.19.0-15
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6
IBM Automation Decision Services - update to 23.0.2.0.1

External References

Related Security Bulletins