CVE-2024-40705Asymmetric Resource Consumption (Amplification) in IBM Infosphere Information Server

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 74.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 15

Description

IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID: 298279.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDibm/infosphere_information_server11.7, 11.7.0.1, 11.7.0.2+2

🔴Vulnerability Details

2
GHSA
GHSA-f5ch-pqm5-5632: IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads2024-08-15
CVEList
IBM InfoSphere Information Server denial of service2024-08-15
CVE-2024-40705 — IBM vulnerability | cvebase