IBM B2B Advanced Communication denial of service
CVE-2023-24971

7.5HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
31 July 2023

Summary

The vulnerability allows an attacker to exploit a deserialization flaw in IBM B2B Advanced Communications and IBM Multi-Enterprise Integration Gateway. By sending untrusted serialized Java objects, an attacker could cause a denial of service, potentially disrupting service availability. To mitigate this risk, users should ensure that their systems are updated to the latest versions and apply recommended security patches.

Affected Version(s)

B2B Advanced Communications 1.0.0.0

Multi-Enterprise Integration Gateway 1.0.0.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.