NULL pointer dereference in ws - CVE-2024-37890

 

NULL pointer dereference in ws - CVE-2024-37890

Published: July 15, 2024


Vulnerability identifier: #VU94329
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-37890
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error when handling requests with the number of headers that exceeds the "server.maxHeadersCount" value. A remote attacker can send a specially crafted request to the application and perform a denial of service (DoS) attack.


Affected software

ws
Astronomer with IBM
Software Support app (Android)
console
Software Support App (iOS)
Security QRadar EDR
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
Cloud Pak for Network Automation
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Cognos Dashboards on Cloud Pak for Data
QRadar Log Source Management App
Maximo Application Suite - Monitor Component
QRadar Suite
App Connect Enterprise Certified Container
IBM Maximo Application Suite - Manage Component
IBM Observability with Instana
IBM Cloud Transformation Advisor
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
Confluence Data Center
IBM Spectrum Protect Plus
Fedora
Voice Gateway
yarnpkg
Planning Analytics Local
IBM Cloud Pak System
HPE Unified OSS Console (UOC)
OpenShift Data Foundation (formerly OpenShift Container Storage)
Confluence Server
IBM App Connect Enterprise

How to mitigate CVE-2024-37890

Install updates from vendor's website.

ws - addressed in versions 5.2.4, 6.2.3, 7.5.10, 8.17.1
Astronomer with IBM - update to 1.0.1
Software Support app (Android) - update to 2.0.0
console - update to 1.7.2
Software Support App (iOS) - update to 2.0.0
QRadar Suite - update to 1.10.25.0
Security QRadar EDR - update to 3.12.10
App Connect Enterprise Certified Container - addressed in versions 5.0.20, 12.2.0
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.27, 8.7.21, 9.0.14
IBM Observability with Instana - update to 277
Voice Gateway - addressed in versions 1.0.8.12, 1.0.8.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
Cognos Analytics Mobile (Android) - update to 1.1.20
yarnpkg - addressed in versions 1.22.22-5.el9, 1.22.22-5.fc39, 1.22.22-5.fc40, 1.22.22-5.fc41
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
Cloud Pak for Network Automation - update to 2.7.5
HPE Unified OSS Console (UOC) - update to 3.1.8
IBM Cloud Transformation Advisor - update to 3.10.1
IBM Decision Optimization for Cloud Pak for Data - update to 4.8
DB2 on Cloud Pak for Data - update to 4.8.8
DB2 Warehouse on Cloud Pak for Data - update to 4.8.8
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.14.18, 4.15.14, 4.16.0, 4.16.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.3
Cognos Dashboards on Cloud Pak for Data - update to 5.1
QRadar Log Source Management App - update to 7.0.11
Confluence Data Center - addressed in versions 8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2, 10.1.0
Confluence Server - addressed in versions 8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2, 10.1.0
Maximo Application Suite - Monitor Component - addressed in versions 8.10.13, 8.11.10, 9.0.2
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM App Connect Enterprise - update to 12.0.12.4

External References

Related Security Bulletins