CVE-2023-34396: Apache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart forms
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2.
Upgrade to Struts 2.5.31 or 6.1.2.1 or greater
Other sources
Apache Struts is vulnerable to a denial of service, caused by a flaw when processing Multipart request containing non-file normal form fields. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Strutsto a version that resolves this vulnerability.Fixed in 2.5.31 - Upgrade
Upgrade
Apache Strutsto a version that resolves this vulnerability.Fixed in 6.1.2.1
Event History
Frequently Asked Questions
What is the vulnerability ID of this Apache Struts vulnerability?
The vulnerability ID is CVE-2023-34396.
What is the severity of CVE-2023-34396?
The severity of CVE-2023-34396 is high with a severity value of 7.5.
How does the vulnerability in Apache Struts affect IBM QRadar SIEM?
The vulnerability affects IBM QRadar SIEM version 7.5.0 - 7.5.0 UP6.
What is the impact of CVE-2023-34396?
The vulnerability can be exploited by a remote attacker to cause a denial of service condition.
Where can I find more information about CVE-2023-34396?
You can find more information about CVE-2023-34396 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/257946), [Reference 2](https://www.ibm.com/support/pages/node/7049133).