IBM WebSphere Application Server Vulnerable to Denial of Service Attack
CVE-2024-25026
7.5HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 25 April 2024
What is CVE-2024-25026?
IBM WebSphere Application Server versions 8.5, 9.0, and Liberty versions 17.0.0.3 through 24.0.0.4 are susceptible to a denial of service attack. This vulnerability can be exploited by sending specially crafted requests that lead the server to excessively consume memory resources, potentially disrupting service availability. Organizations using affected versions are advised to review their security practices and consider applying patches provided by IBM to mitigate associated risks.
Affected Version(s)
WebSphere Application Server 8.5, 9.0
WebSphere Application Server Liberty 17.0.0.3 <= 24.0.0.4