IBM SDK Vulnerable to Denial of Service Attack
CVE-2023-38264
5.9MEDIUM
What is CVE-2023-38264?
The IBM SDK, Java Technology Edition, specifically in its Object Request Broker (ORB) components across various versions, is susceptible to denial of service attacks under certain conditions. This vulnerability arises from improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters, potentially allowing attackers to exploit this flaw and disrupt service availability. Immediate attention and remediation are recommended to mitigate risks associated with this vulnerability.
Affected Version(s)
SDK, Java Technology Edition 7.1.0.0 <= 7.1.5.21
SDK, Java Technology Edition 8.0.0.0 <= 8.0.8.21