SB2024022621 - Reliance on reverse DNS resolution for a security-critical action in IBM Instana Observability
Published: February 26, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Reliance on Reverse DNS Resolution for a Security-Critical Action (CVE-ID: CVE-2023-37404)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to reliance on reverse DNS resolution for a security-critical action. A remote unauthenticated attacker can execute arbitrary code on the host after a successful DNS poisoning attack.
Remediation
Install update from vendor's website.