IBM B2B Advanced Communication denial of service
CVE-2023-24971
7.5HIGH
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 31 July 2023
Summary
The vulnerability allows an attacker to exploit a deserialization flaw in IBM B2B Advanced Communications and IBM Multi-Enterprise Integration Gateway. By sending untrusted serialized Java objects, an attacker could cause a denial of service, potentially disrupting service availability. To mitigate this risk, users should ensure that their systems are updated to the latest versions and apply recommended security patches.
Affected Version(s)
B2B Advanced Communications 1.0.0.0
Multi-Enterprise Integration Gateway 1.0.0.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved