BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2023
CVE-2023-36478High confidence

HTTP/2 HPACK integer overflow and buffer allocation

eclipse · jetty.project

Official source article: GitHub GHSA-WGH7-54F2-X98R ↗. Check the applicable product and release in the original source.

7.5HighCVSS 3.1
Recommended action
Within 7 days

High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.

Patch available
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityHighOperational priority:Critical, raised one band.upgradedsince 13 Feb 2025

Evidence used

  • No CISA KEV confirmation is currently recorded.
  • A structured source references public exploit or proof-of-concept material.
  • The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
  • EPSS is 3.75% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict the affected network interface to trusted sources where business-safe.
  • Increase monitoring for the attack path and post-exploitation behaviour described in the report.

Verification

  1. Confirm that the asset runs eclipse jetty.project and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 3 daysRemediation target: Within 90 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Distribution package intelligence

Release-specific package status

Alpine, Debian findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.

7 package states
Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Distribution releaseSource packageVendor stateFixed versionEvidence
Alpine v3.23v3.23 · communityjetty-runnerVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.9.4.53.20231009-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · communityjetty-runnerVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.9.4.53.20231009-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.21v3.21 · communityjetty-runnerVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.9.4.53.20231009-r0Alpine Security Database ↗Source updated 19 Aug 2026
Debian trixietrixie · sourcejetty9Vendor fix publishedDebian records a fixed source-package version for this release.9.4.53-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian bookwormbookworm · sourcejetty9Vendor fix publishedDebian records a fixed source-package version for this release.9.4.50-4+deb12u2Debian Security Tracker ↗Source updated 6 Oct 2026
Debian forkyforky · sourcejetty9Vendor fix publishedDebian records a fixed source-package version for this release.9.4.53-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian sidsid · sourcejetty9Vendor fix publishedDebian records a fixed source-package version for this release.9.4.53-1Debian Security Tracker ↗Source updated 6 Oct 2026
Open-source package ranges10 source-attributed ranges

These OSV and GitHub advisory ranges apply only to the named package and ecosystem. A listed fixed version is not a universal product patch or proof that an update is installed.

Ecosystem and packageAffected rangeFirst fixed versionEvidence
Mavenorg.eclipse.jetty.http2:http2-hpackECOSYSTEM: introduced 10.0.0; fixed 10.0.1610.0.16OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.eclipse.jetty.http2:http2-hpackECOSYSTEM: introduced 11.0.0; fixed 11.0.1611.0.16OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.eclipse.jetty.http2:http2-hpackECOSYSTEM: introduced 9.3.0; fixed 9.4.539.4.53OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.eclipse.jetty.http3:http3-qpackECOSYSTEM: introduced 10.0.0; fixed 10.0.1610.0.16OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.eclipse.jetty.http3:http3-qpackECOSYSTEM: introduced 11.0.0; fixed 11.0.1611.0.16OSV record ↗aggregator derived · 10 Sep 2026
mavenorg.eclipse.jetty.http2:http2-hpack>= 10.0.0, <= 10.0.1510.0.16GitHub advisory ↗upstream repository advisory · 16 Oct 2025
mavenorg.eclipse.jetty.http2:http2-hpack>= 11.0.0, <= 11.0.1511.0.16GitHub advisory ↗upstream repository advisory · 16 Oct 2025
mavenorg.eclipse.jetty.http2:http2-hpack>= 9.3.0, <= 9.4.529.4.53GitHub advisory ↗upstream repository advisory · 16 Oct 2025
mavenorg.eclipse.jetty.http3:http3-qpack>= 10.0.0, <= 10.0.1510.0.16GitHub advisory ↗upstream repository advisory · 16 Oct 2025
mavenorg.eclipse.jetty.http3:http3-qpack>= 11.0.0, <= 11.0.1511.0.16GitHub advisory ↗upstream repository advisory · 16 Oct 2025
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

1 current
CVE-2023-36478 · CSAF 2.0 · revision 3 · finalRed Hat Product Securityjetty: hpack header values cause denial of service in http/2
11 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • jenkins.src as a component of OpenShift Developer Tools and Services
  • http2-hpack as a component of Red Hat Integration Camel Quarkus 2
  • jetty as a component of Red Hat JBoss Fuse 6
  • jetty as a component of Red Hat JBoss Fuse Service Works 6
  • jenkins as a component of Red Hat OpenShift Container Platform 3.11
  • jenkins.src as a component of Red Hat OpenShift Container Platform 3.11
  • jetty-project as a component of Red Hat OpenShift Container Platform 3.11
  • jenkins as a component of Red Hat OpenShift Container Platform 4
  • jenkins.src as a component of Red Hat OpenShift Container Platform 4
  • puppetserver as a component of Red Hat Satellite 6
  • puppetserver.src as a component of Red Hat Satellite 6
Summary
A flaw was found in Jetty http2-hpack and http3-qpack. If header values exceed the size limit and Huffman is the true`MetaDataBuilder.checkSize`, the multiplication will overflow, and the length will become negative, causing a large buffer allocation on the server, leading to a Denial of Service (DoS) attack.
Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2023-2828

No EUVD known-exploited evidence

ENISA has published the identifier mapping but no EUVD description has been stored yet.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
Not supplied in the stored EUVD record
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days

High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.

Patch available
01

What, why and how

Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in `MetaDataBuilder.checkSize` allows for HTTP/2 HPACK header values to exceed their size limit. `MetaDataBuilder.java` determines if a header name or value exceeds the size limit, and throws an exception if the limit is exceeded. However, when length is very large and huffman is true, the multiplication by 4 in line 295 will overflow, and length will become negative. `(_size+length)` will now be negative, and the check on line 296 will not be triggered. Furthermore, `MetaDataBuilder.checkSize` allows for user-entered HPACK header value sizes to be negative, potentially leading to a very large buffer allocation later on when the user-entered size is multiplied by 2. This means that if a user provides a negative length value (or, more precisely, a length value which, when multiplied by the 4/3 fudge factor, is negative), and this length value is a very large positive number when multiplied by 2, then the user can cause a very large buffer to be allocated on the server. Users of HTTP/2 can be impacted by a remote denial of service attack. The issue has been fixed in versions 11.0.16, 10.0.16, and 9.4.53. There are no known workarounds.

What

Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in `MetaDataBuilder.checkSize` allows for HTTP/2 HPACK header values to exceed their size limit. `MetaDataBuilder.java` determines if a header name or value exceeds the size limit, and throws an exception if the limit is exceeded. However, when length is very large and huffman is true, the multiplication by 4 in line 295 will overflow, and length will become negative. `(_size+length)` will now be negative, and the check on line 296 will not be triggered. Furthermore, `MetaDataBuilder.checkSize` allows for user-entered HPACK header value sizes to be negative, potentially leading to a very large buffer allocation later on when the user-entered size is multiplied by 2. This means that if a user provides a negative length value (or, more precisely, a length value which, when multiplied by the 4/3 fudge factor, is negative), and this length value is a very large positive number when multiplied by 2, then the user can cause a very large buffer to be allocated on the server. Users of HTTP/2 can be impacted by a remote denial of service attack. The issue has been fixed in versions 11.0.16, 10.0.16, and 9.4.53. There are no known workarounds.

Why

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may disrupt the affected service.

What

Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in `MetaDataBuilder.checkSize` allows for HTTP/2 HPACK header values to exceed their size limit. `MetaDataBuilder.java` determines if a header name or value exceeds the size limit, and throws an exception if the limit is exceeded. However, when length is very large and huffman is true, the multiplication by 4 in line 295 will overflow, and length will become negative. `(_size+length)` will now be negative, and the check on line 296 will not be triggered. Furthermore, `MetaDataBuilder.checkSize` allows for user-entered HPACK header value sizes to be negative, potentially leading to a very large buffer allocation later on when the user-entered size is multiplied by 2. This means that if a user provides a negative length value (or, more precisely, a length value which, when multiplied by the 4/3 fudge factor, is negative), and this length value is a very large positive number when multiplied by 2, then the user can cause a very large buffer to be allocated on the server. Users of HTTP/2 can be impacted by a remote denial of service attack. The issue has been fixed in versions 11.0.16, 10.0.16, and 9.4.53. There are no known workarounds.

Why

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may disrupt the affected service.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Reference recorded

A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.

Likely attack path
a network path → Integer Overflow or Wraparound → disrupt the affected service
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-190 ↗

CWE-190: Integer Overflow or Wraparound. The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CNoneConfidentiality impact: No direct loss is represented by this metric.INoneIntegrity impact: No direct loss is represented by this metric.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedDenial of serviceCWE-190Public exploit reference
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

BSI · German · WID-SEC-2024-3684IBM QRadar SIEM: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen offenzulegen oder einen Spoofing-Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2024-1637Oracle Fusion Middleware: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0106Oracle Communications: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0094Atlassian Bamboo: Mehrere Schwachstellen

Ein entfernter Angreifer kann mehrere Schwachstellen in Atlassian Bamboo ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen oder einen Request Smuggling-Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2023-2627Eclipse Jetty: Mehrere Schwachstellen ermöglichen Denial of Service

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um einen Denial of Service Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2024-0101Atlassian Bitbucket: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Atlassian Bitbucket ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder Request-Smuggling-Angriffe durchzuführen.

Official advisory ↗
Cyber Security Agency of Singapore · English · CSA-SB-20231011Security Bulletin 11 Oct 2023

The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 11 Oct 2023, published on 11 October 2023. Open the linked bulletin for the product, severity and reference information published in that issue.

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBM

cord?id=CVE-2023-2976 Référence CVE CVE-2023-33201 https://www.cve.org/CVERecord?id=CVE-2023-33201 Référence CVE CVE-2023-34453 https://www.cve.org/CVERecord?id=CVE-2023-34453 Référence CVE CVE-2023-34454 https://www.cve.org/CVERecord?id=CVE-2023-34454 Référence CVE CVE-2023-34455 https://www.cve.org/CVERecord?id=CVE-2023-34455 Référence CVE CVE-2023-34462 https://www.cve.org/CVERecord?id=CVE-2023-34462 Référence CVE CVE-2023-34610 https://www.cve.org/CVERecord?id=CVE-2023-34610 Référence CVE CVE-2023-35701 https://www.cve.org/CVERecord?id=CVE-2023-35701 Référence CVE CVE-2023-3635 https://www.cve.org/CVERecord?id=CVE-2023-3635 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-39410 https://www.cve.org/CVERecord?id=CVE-2023-39410 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-43642 https://www.cve.org/CVERecord?id=CVE-2023-43642 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-44981 https://www.cve.org/CVERecord?id=CVE-2023-44981 Référence CVE CVE-2023-45178 https://www.cve.org/CVERecord?id=CVE-2023-45178 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0255Multiples vulnérabilités dans les produits IBM

upport/pages/node/7229377 Référence CVE CVE-2022-4304 https://www.cve.org/CVERecord?id=CVE-2022-4304 Référence CVE CVE-2022-45688 https://www.cve.org/CVERecord?id=CVE-2022-45688 Référence CVE CVE-2023-0215 https://www.cve.org/CVERecord?id=CVE-2023-0215 Référence CVE CVE-2023-0286 https://www.cve.org/CVERecord?id=CVE-2023-0286 Référence CVE CVE-2023-26048 https://www.cve.org/CVERecord?id=CVE-2023-26048 Référence CVE CVE-2023-26049 https://www.cve.org/CVERecord?id=CVE-2023-26049 Référence CVE CVE-2023-28439 https://www.cve.org/CVERecord?id=CVE-2023-28439 Référence CVE CVE-2023-33201 https://www.cve.org/CVERecord?id=CVE-2023-33201 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-41900 https://www.cve.org/CVERecord?id=CVE-2023-41900 Référence CVE CVE-2023-5072 https://www.cve.org/CVERecord?id=CVE-2023-5072 Référence CVE CVE-2024-26935 https://www.cve.org/CVERecord?id=CVE-2024-26935 Référence CVE CVE-2024-3661 https://www.cve.org/CVERecord?id=CVE-2024-3661 Référence CVE CVE-2024-46695 https://www.cve.org/CVERecord?id=CVE-2024-46695 Référence CVE CVE-2024-49949 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-1081Multiples vulnérabilités dans les produits IBM

ord?id=CVE-2023-23613 Référence CVE CVE-2023-2976 https://www.cve.org/CVERecord?id=CVE-2023-2976 Référence CVE CVE-2023-31582 https://www.cve.org/CVERecord?id=CVE-2023-31582 Référence CVE CVE-2023-33546 https://www.cve.org/CVERecord?id=CVE-2023-33546 Référence CVE CVE-2023-34453 https://www.cve.org/CVERecord?id=CVE-2023-34453 Référence CVE CVE-2023-34454 https://www.cve.org/CVERecord?id=CVE-2023-34454 Référence CVE CVE-2023-34455 https://www.cve.org/CVERecord?id=CVE-2023-34455 Référence CVE CVE-2023-34462 https://www.cve.org/CVERecord?id=CVE-2023-34462 Référence CVE CVE-2023-35116 https://www.cve.org/CVERecord?id=CVE-2023-35116 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-37920 https://www.cve.org/CVERecord?id=CVE-2023-37920 Référence CVE CVE-2023-43642 https://www.cve.org/CVERecord?id=CVE-2023-43642 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-48161 https://www.cve.org/CVERecord?id=CVE-2023-48161 Référence CVE CVE-2023-52425 https://www.cve.org/CVERecord?id=CVE-2023-52425 Référence CVE CVE-2023-52426 https://www.cve.org/CVERecord?id=CVE-2023-52426 Référence CVE CVE-2023-52428 https://www.cve.org/CVERecord?id=CVE-2023-52428 Référence CVE CVE-2024-0450 https://www.cve.org/CVERecord?id=C

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0459Multiples vulnérabilités dans les produits IBM

d?id=CVE-2021-21295 Référence CVE CVE-2021-31684 https://www.cve.org/CVERecord?id=CVE-2021-31684 Référence CVE CVE-2022-1996 https://www.cve.org/CVERecord?id=CVE-2022-1996 Référence CVE CVE-2022-36364 https://www.cve.org/CVERecord?id=CVE-2022-36364 Référence CVE CVE-2022-42003 https://www.cve.org/CVERecord?id=CVE-2022-42003 Référence CVE CVE-2022-42004 https://www.cve.org/CVERecord?id=CVE-2022-42004 Référence CVE CVE-2022-46337 https://www.cve.org/CVERecord?id=CVE-2022-46337 Référence CVE CVE-2023-261257 https://www.cve.org/CVERecord?id=CVE-2023-261257 Référence CVE CVE-2023-34462 https://www.cve.org/CVERecord?id=CVE-2023-34462 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-38729 https://www.cve.org/CVERecord?id=CVE-2023-38729 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-41900 https://www.cve.org/CVERecord?id=CVE-2023-41900 Référence CVE CVE-2023-44270 https://www.cve.org/CVERecord?id=CVE-2023-44270 Référence CVE CVE-2023-44981 https://www.cve.org/CVERecord?id=CVE-2023-44981 Référence CVE CVE-2023-45857 https://www.cve.org/CVERecord?id=CVE-2023-45857 Référence CVE CVE-2023-49083 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0385Multiples vulnérabilités dans les produits IBM

ecord?id=CVE-2023-33203 Référence CVE CVE-2023-33850 https://www.cve.org/CVERecord?id=CVE-2023-33850 Référence CVE CVE-2023-33951 https://www.cve.org/CVERecord?id=CVE-2023-33951 Référence CVE CVE-2023-33952 https://www.cve.org/CVERecord?id=CVE-2023-33952 Référence CVE CVE-2023-34241 https://www.cve.org/CVERecord?id=CVE-2023-34241 Référence CVE CVE-2023-35823 https://www.cve.org/CVERecord?id=CVE-2023-35823 Référence CVE CVE-2023-35824 https://www.cve.org/CVERecord?id=CVE-2023-35824 Référence CVE CVE-2023-3609 https://www.cve.org/CVERecord?id=CVE-2023-3609 Référence CVE CVE-2023-3611 https://www.cve.org/CVERecord?id=CVE-2023-3611 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-3772 https://www.cve.org/CVERecord?id=CVE-2023-3772 Référence CVE CVE-2023-3812 https://www.cve.org/CVERecord?id=CVE-2023-3812 Référence CVE CVE-2023-38325 https://www.cve.org/CVERecord?id=CVE-2023-38325 Référence CVE CVE-2023-38546 https://www.cve.org/CVERecord?id=CVE-2023-38546 Référence CVE CVE-2023-40283 https://www.cve.org/CVERecord?id=CVE-2023-40283 Référence CVE CVE-2023-4128 https://www.cve.org/CVERecord?id=CVE-2023-4128 Référence CVE CVE-2023-4132 https://www.cve.org/CVERecord?id=CVE-2023-4132 Référence CVE CVE-2023-4155 https://www.cve.org/CVERecord?id=CVE-2023-

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0228Multiples vulnérabilités dans IBM

ecord?id=CVE-2023-22081 Référence CVE CVE-2023-24998 https://www.cve.org/CVERecord?id=CVE-2023-24998 Référence CVE CVE-2023-2597 https://www.cve.org/CVERecord?id=CVE-2023-2597 Référence CVE CVE-2023-2976 https://www.cve.org/CVERecord?id=CVE-2023-2976 Référence CVE CVE-2023-33850 https://www.cve.org/CVERecord?id=CVE-2023-33850 Référence CVE CVE-2023-34034 https://www.cve.org/CVERecord?id=CVE-2023-34034 Référence CVE CVE-2023-34453 https://www.cve.org/CVERecord?id=CVE-2023-34453 Référence CVE CVE-2023-34454 https://www.cve.org/CVERecord?id=CVE-2023-34454 Référence CVE CVE-2023-34455 https://www.cve.org/CVERecord?id=CVE-2023-34455 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-38039 https://www.cve.org/CVERecord?id=CVE-2023-38039 Référence CVE CVE-2023-39685 https://www.cve.org/CVERecord?id=CVE-2023-39685 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-41900 https://www.cve.org/CVERecord?id=CVE-2023-41900 Référence CVE CVE-2023-43642 https://www.cve.org/CVERecord?id=CVE-2023-43642 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-44981 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0199Multiples vulnérabilités dans IBM

d?id=CVE-2023-22045 Référence CVE CVE-2023-22049 https://www.cve.org/CVERecord?id=CVE-2023-22049 Référence CVE CVE-2023-22067 https://www.cve.org/CVERecord?id=CVE-2023-22067 Référence CVE CVE-2023-22081 https://www.cve.org/CVERecord?id=CVE-2023-22081 Référence CVE CVE-2023-22602 https://www.cve.org/CVERecord?id=CVE-2023-22602 Référence CVE CVE-2023-25153 https://www.cve.org/CVERecord?id=CVE-2023-25153 Référence CVE CVE-2023-25173 https://www.cve.org/CVERecord?id=CVE-2023-25173 Référence CVE CVE-2023-33850 https://www.cve.org/CVERecord?id=CVE-2023-33850 Référence CVE CVE-2023-34478 https://www.cve.org/CVERecord?id=CVE-2023-34478 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-39325 https://www.cve.org/CVERecord?id=CVE-2023-39325 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-40743 https://www.cve.org/CVERecord?id=CVE-2023-40743 Référence CVE CVE-2023-41900 https://www.cve.org/CVERecord?id=CVE-2023-41900 Référence CVE CVE-2023-42282 https://www.cve.org/CVERecord?id=CVE-2023-42282 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45857 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0180Multiples vulnérabilités dans les produits IBM

Record?id=CVE-2023-2597 Référence CVE CVE-2023-26115 https://www.cve.org/CVERecord?id=CVE-2023-26115 Référence CVE CVE-2023-26136 https://www.cve.org/CVERecord?id=CVE-2023-26136 Référence CVE CVE-2023-2650 https://www.cve.org/CVERecord?id=CVE-2023-2650 Référence CVE CVE-2023-30588 https://www.cve.org/CVERecord?id=CVE-2023-30588 Référence CVE CVE-2023-30589 https://www.cve.org/CVERecord?id=CVE-2023-30589 Référence CVE CVE-2023-30996 https://www.cve.org/CVERecord?id=CVE-2023-30996 Référence CVE CVE-2023-32344 https://www.cve.org/CVERecord?id=CVE-2023-32344 Référence CVE CVE-2023-3446 https://www.cve.org/CVERecord?id=CVE-2023-3446 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-3817 https://www.cve.org/CVERecord?id=CVE-2023-3817 Référence CVE CVE-2023-38359 https://www.cve.org/CVERecord?id=CVE-2023-38359 Référence CVE CVE-2023-39410 https://www.cve.org/CVERecord?id=CVE-2023-39410 Référence CVE CVE-2023-43051 https://www.cve.org/CVERecord?id=CVE-2023-43051 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45133 https://www.cve.org/CVERecord?id=CVE-2023-45133 Référence CVE CVE-2023-45857 https://www.cve.org/CVERecord?id=CVE-2023-45857 Référence CVE CVE-2023-46158 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0113Multiples vulnérabilités dans les produits IBM

d?id=CVE-2023-32002 Référence CVE CVE-2023-32006 https://www.cve.org/CVERecord?id=CVE-2023-32006 Référence CVE CVE-2023-32559 https://www.cve.org/CVERecord?id=CVE-2023-32559 Référence CVE CVE-2023-34149 https://www.cve.org/CVERecord?id=CVE-2023-34149 Référence CVE CVE-2023-34396 https://www.cve.org/CVERecord?id=CVE-2023-34396 Référence CVE CVE-2023-34453 https://www.cve.org/CVERecord?id=CVE-2023-34453 Référence CVE CVE-2023-34454 https://www.cve.org/CVERecord?id=CVE-2023-34454 Référence CVE CVE-2023-34455 https://www.cve.org/CVERecord?id=CVE-2023-34455 Référence CVE CVE-2023-34462 https://www.cve.org/CVERecord?id=CVE-2023-34462 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-41900 https://www.cve.org/CVERecord?id=CVE-2023-41900 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-46308 https://www.cve.org/CVERecord?id=CVE-2023-46308 Référence CVE CVE-2023-46849 https://www.cve.org/CVERecord?id=CVE-2023-46849 Référence CVE CVE-2023-46850 https://www.cve.org/CVERecord?id=CVE-2023-46850 Référence CVE CVE-2023-4807 https://www.cve.org/CVERecord?id=C

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0074Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM . Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0057Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM . Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0031Multiples vulnérabilités dans les produits IBM

d?id=CVE-2021-21295 Référence CVE CVE-2021-21409 https://www.cve.org/CVERecord?id=CVE-2021-21409 Référence CVE CVE-2021-25741 https://www.cve.org/CVERecord?id=CVE-2021-25741 Référence CVE CVE-2021-37136 https://www.cve.org/CVERecord?id=CVE-2021-37136 Référence CVE CVE-2021-37137 https://www.cve.org/CVERecord?id=CVE-2021-37137 Référence CVE CVE-2021-38153 https://www.cve.org/CVERecord?id=CVE-2021-38153 Référence CVE CVE-2021-43797 https://www.cve.org/CVERecord?id=CVE-2021-43797 Référence CVE CVE-2023-22036 https://www.cve.org/CVERecord?id=CVE-2023-22036 Référence CVE CVE-2023-22049 https://www.cve.org/CVERecord?id=CVE-2023-22049 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-41900 https://www.cve.org/CVERecord?id=CVE-2023-41900 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-47145 https://www.cve.org/CVERecord?id=CVE-2023-47145 Gestion détaillée du document le 12 janvier 2024 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gou

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-1062Multiples vulnérabilités dans Juniper Secure Analytics

De multiples vulnérabilités ont été découvertes dans Juniper Secure Analytics. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-1055Multiples vulnérabilités dans les produits IBM

ecord?id=CVE-2022-45693 Référence CVE CVE-2023-1436 https://www.cve.org/CVERecord?id=CVE-2023-1436 Référence CVE CVE-2023-22045 https://www.cve.org/CVERecord?id=CVE-2023-22045 Référence CVE CVE-2023-22049 https://www.cve.org/CVERecord?id=CVE-2023-22049 Référence CVE CVE-2023-26049 https://www.cve.org/CVERecord?id=CVE-2023-26049 Référence CVE CVE-2023-32233 https://www.cve.org/CVERecord?id=CVE-2023-32233 Référence CVE CVE-2023-3341 https://www.cve.org/CVERecord?id=CVE-2023-3341 Référence CVE CVE-2023-34040 https://www.cve.org/CVERecord?id=CVE-2023-34040 Référence CVE CVE-2023-35001 https://www.cve.org/CVERecord?id=CVE-2023-35001 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-37920 https://www.cve.org/CVERecord?id=CVE-2023-37920 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-40787 https://www.cve.org/CVERecord?id=CVE-2023-40787 Référence CVE CVE-2023-41080 https://www.cve.org/CVERecord?id=CVE-2023-41080 Référence CVE CVE-2023-41835 https://www.cve.org/CVERecord?id=CVE-2023-41835 Référence CVE CVE-2023-42795 https://www.cve.org/CVERecord?id=CVE-2023-42795 Référence CVE CVE-2023-43804 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0976Multiples vulnérabilités dans les produits IBM

ord?id=CVE-2022-41854 Référence CVE CVE-2022-41966 https://www.cve.org/CVERecord?id=CVE-2022-41966 Référence CVE CVE-2022-45061 https://www.cve.org/CVERecord?id=CVE-2022-45061 Référence CVE CVE-2022-48303 https://www.cve.org/CVERecord?id=CVE-2022-48303 Référence CVE CVE-2023-1255 https://www.cve.org/CVERecord?id=CVE-2023-1255 Référence CVE CVE-2023-24998 https://www.cve.org/CVERecord?id=CVE-2023-24998 Référence CVE CVE-2023-26279 https://www.cve.org/CVERecord?id=CVE-2023-26279 Référence CVE CVE-2023-32001 https://www.cve.org/CVERecord?id=CVE-2023-32001 Référence CVE CVE-2023-34104 https://www.cve.org/CVERecord?id=CVE-2023-34104 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-38039 https://www.cve.org/CVERecord?id=CVE-2023-38039 Référence CVE CVE-2023-41080 https://www.cve.org/CVERecord?id=CVE-2023-41080 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Gestion détaillée du document le 23 novembre 2023 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité de

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2023-015305Eclipse Foundation の Jetty 等複数ベンダの製品における整数オーバーフローの脆弱性

Eclipse Foundation の Jetty 等複数ベンダの製品には、整数オーバーフローの脆弱性、リソースの枯渇に関する脆弱性が存在します。

Official advisory ↗
NCSC-NL · Dutch · NCSC-2024-0298Kwetsbaarheden verholpen in Oracle Fusion Middleware

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: * Denial-of-Service (DoS) * Toegang tot gevoelige gegevens * Toegang tot systeemgegevens * Manipulatie van gegevens * (Remote) code execution (Gebruikersrechten)

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
Fixed
Action
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 10 Oct 2023 · Last source change 13 Feb 2025, 16:56 UTC · CWE-190 · Integer Overflow or Wraparound

CVE recordCVE.org · 5.1
CVSS sourceCNA
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2023-2828
Product sourceVendor CSAF · Red Hat Product Security
Remediation sourceVendor CSAF · Red Hat Product Security
CWE sourceCNA
NVD statusNVD modified after enrichment

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    >= 10.0.0, < 10.0.16; >= 11.0.0, < 11.0.16; >= 9.3.0, < 9.4.53 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    >= 10.0.0, < 10.0.16; >= 11.0.0, < 11.0.16; >= 9.3.0, < 9.4.53 · Fixed: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).
    Red Hat Product Security ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2023-36478 · cve.blacktree.nl