Severity
7.5HIGH
EPSS
0.0%
top 91.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31

Description

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 280400.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/websphere_application_server_liberty17.0.0.324.0.0.4
NVDibm/websphere_application_server17.0.0.324.0.0.3

🔴Vulnerability Details

2
CVEList
IBM WebSphere Application Server Liberty denial of service2024-03-31
GHSA
GHSA-x79w-g5hr-45pg: IBM WebSphere Application Server Liberty 172024-03-31
CVE-2024-22353 (HIGH CVSS 7.5) | IBM WebSphere Application Server Li | cvebase.io