Resource exhaustion in Jetty - CVE-2024-9823

 

Resource exhaustion in Jetty - CVE-2024-9823

Published: October 14, 2024


Vulnerability identifier: #VU98518
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-9823
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within the DoSFilter. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Jetty
Debian Linux
Rational Functional Tester (RFT)
IBM Observability with Instana
Log Analysis
Netcool Operations Insight
IBM Process Mining
Rational Service Tester
IBM Cloud Object Storage Systems
IBM Cloud Pak for Watson AIOps
Rational Performance Tester
Installation Manager
Packaging Utility
Storage Protect Server
DevOps Test UI
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
jetty9 (Debian package)
IBM InfoSphere Information Server

How to mitigate CVE-2024-9823

Install updates from vendor's website.

Jetty - addressed in versions 9.4.54.v20240207, 10.0.18, 11.0.18, 12.0.3
IBM Observability with Instana - addressed in versions 1.0.293, 1.0.309
Log Analysis - update to 1.3.8.2
Netcool Operations Insight - update to 1.6.15
IBM Process Mining - update to 2.0
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 11 IF01
Rational Service Tester - update to 11.0.4
Rational Performance Tester - update to 11.0.4
Installation Manager - update to 1.10.1.1
Packaging Utility - update to 1.10.1.1
IBM Cloud Object Storage Systems - addressed in versions 3.18.0.84, 3.18.5.40
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
Storage Protect Server - update to 8.1.26
jetty9 (Debian package) - update to 9.4.57-0+deb12u1
DevOps Test UI - update to 11.0.4
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5

External References

Related Security Bulletins