CVE-2024-27268Allocation of Resources Without Limits or Throttling in IBM Websphere Application Server

Severity
7.5HIGHNVD
CNA5.9
EPSS
0.2%
top 61.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateMay 4

Description

IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 284574.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/websphere_application_server_liberty18.0.0.224.0.0.4
NVDibm/websphere_application_server18.0.0.224.0.0.5

🔴Vulnerability Details

2
GHSA
GHSA-jf7f-5899-cj5x: IBM WebSphere Application Server Liberty 182024-04-04
CVEList
IBM WebSphere Application Server Liberty denial of service2024-04-04

📋Vendor Advisories

1
Red Hat
ibm-WebSphere: CONTINUATION frames DoS2024-05-04
CVE-2024-27268 — IBM vulnerability | cvebase