IBM SDK Vulnerable to Denial of Service Attack
CVE-2023-38264

5.9MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
14 May 2024

Summary

The IBM SDK, Java Technology Edition, specifically in its Object Request Broker (ORB) components across various versions, is susceptible to denial of service attacks under certain conditions. This vulnerability arises from improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters, potentially allowing attackers to exploit this flaw and disrupt service availability. Immediate attention and remediation are recommended to mitigate risks associated with this vulnerability.

Affected Version(s)

SDK, Java Technology Edition 7.1.0.0 <= 7.1.5.21

SDK, Java Technology Edition 8.0.0.0 <= 8.0.8.21

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.