CVE-2023-28949: IBM Engineering Requirements Management cross-site request forgery
FasterXML jackson-databind is vulnerable to a denial of service, caused by an error when using JDK serialization to serialize and deserialize JsonNode values. By sending a specially crafted request, an attacker could exploit this vulnerability to cause a denial of service.
Other sources
IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 251216.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28949?
CVE-2023-28949 has been classified as a denial of service vulnerability.
How do I fix CVE-2023-28949?
To fix CVE-2023-28949, upgrade your IBM Engineering Requirements Management DOORS or DOORS Web Access to version 9.7.2.8 or later.
Which software is affected by CVE-2023-28949?
CVE-2023-28949 affects IBM Engineering Requirements Management DOORS and IBM Engineering Requirements Management DOORS Web Access version up to 9.7.2.7.
What type of attack can be conducted using CVE-2023-28949?
An attacker can exploit CVE-2023-28949 to conduct a denial of service attack by sending specially crafted requests.
What is the cause of CVE-2023-28949?
CVE-2023-28949 is caused by an error in JDK serialization when serializing and deserializing JsonNode values.