Resource management error in json-smart - CVE-2024-57699

 

Resource management error in json-smart - CVE-2024-57699

Published: April 3, 2025


Vulnerability identifier: #VU106926
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-57699
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application when handling a specially crafted JSON input. A remote attacker can pass a large number of ’{’ characters to the application and perform a denial of service (DoS) attack.

Note, the vulnerability exists due to incomplete fix for #VU75044 (CVE-2023-1370).


Affected software

json-smart
OpenShift Developer Tools and Services
Red Hat Camel for Spring Boot
IBM App Connect Enterprise
IBM Observability with Instana
Netcool Operations Insight
Oracle Communications Converged Charging System
IBM Watson Knowledge Catalog in Cloud Pak for Data
Crucible Server
Jira Service Management Data Center
Jira Service Management Server
Crowd Data Center
Oracle Communications Unified Inventory Management
Confluence Data Center
Bitbucket Data Center
Bamboo Server
Jira Software Data Center
Oracle Banking APIs
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
IBM Cloud Pak for Security
IBM Cloud Transformation Advisor
Datastax Enterprise with IBM
Storage Defender - Resiliency Service
Cloudera Observability with IBM
IBM Cloud Pak for Watson AIOps
Knowledge Catalog Premium Cartridge
Oracle Business Intelligence Enterprise Edition
Oracle Financial Services Analytical Applications Infrastructure
Oracle Policy Automation
Oracle Application Testing Suite
Oracle Banking Digital Experience
Business Automation Insights
Application Modernization Accelerator
webMethods Managed File Transfer
watsonx.data
Oracle Solaris Cluster
openEuler
Oracle Utilities Application Framework
Oracle Insurance Policy Administration
GoldenGate Veridata
Oracle Banking Origination
Stream Analytics
Communications Unified Assurance
Crowd Server
Oracle Communications Order and Service Management
Confluence Server
Bitbucket Server
Oracle WebLogic Server
Primavera Gateway
Jira Software Server
IBM DB2
Oracle Commerce Guided Search
Primavera Unifier
IBM Cloud Pak for Multicloud Management
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Network Slice Selection Function
Planning Analytics Local
json-smart
json-smart-javadoc
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)

How to mitigate CVE-2024-57699

Install updates from vendor's website.

json-smart - update to 2.5.2
IBM Observability with Instana - update to 1.0.297
Netcool Operations Insight - update to 1.6.15
Storage Defender - Resiliency Service - update to 2.0.14
watsonx.data - update to 2.2
Cloudera Observability with IBM - update to 3.6.2
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
Crucible Server - update to 4.9.1
Knowledge Catalog Premium Cartridge - update to 5.2
Jira Service Management Data Center - addressed in versions 5.12.22, 10.3.5, 10.3.17, 10.5.1, 11.3.3
Jira Service Management Server - addressed in versions 5.12.22, 10.3.5, 10.3.17, 10.5.1, 11.3.3
Crowd Server - update to 6.2.4
Crowd Data Center - update to 6.2.4
Confluence Data Center - addressed in versions 8.5.22, 9.2.4, 9.4.1
Confluence Server - addressed in versions 8.5.22, 9.2.4, 9.4.1
Bitbucket Server - addressed in versions 8.9.27, 8.19.18, 9.4.5, 9.5.2, 9.6.2
Bitbucket Data Center - addressed in versions 8.9.27, 8.19.18, 9.4.5, 9.5.2, 9.6.2
Bamboo Server - addressed in versions 9.6.11, 10.2.3
Jira Software Data Center - addressed in versions 9.12.22, 10.3.5, 10.5.1
Jira Software Server - addressed in versions 9.12.22, 10.3.5, 10.5.1
Oracle Policy Automation - update to 12.2.37
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
IBM Cloud Pak for Security - update to 1.11.2.0
Planning Analytics Local - addressed in versions 2.0.0.103, 2.1.10
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
json-smart - update to 2.5.2-1
json-smart-javadoc - update to 2.5.2-1
jenkins (Red Hat package) - addressed in versions 2.504.2.1750846524-3.el9, 2.504.2.1750851690-3.el9, 2.504.2.1750856366-3.el8, 2.504.2.1750857144-3.el9, 2.504.2.1750903189-3.el8, 2.504.2.1750916374-3.el8, 2.504.2.1750932984-3.el8
IBM Cloud Transformation Advisor - update to 4.2.0
Application Modernization Accelerator - update to 4.2.0
Red Hat Camel for Spring Boot - addressed in versions 4.8, 4.8.5
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1750933270-1.el8, 4.13.1750916671-1.el8, 4.14.1750903529-1.el8, 4.15.1750856638-1.el8, 4.16.1750857315-1.el9, 4.17.1750851950-1.el9, 4.18.1750846854-1.el9
Datastax Enterprise with IBM - addressed in versions 6.8.63, 6.9.20
webMethods Managed File Transfer - update to 11.1 Server Fix2
IBM App Connect Enterprise - addressed in versions 12.0.12.14, 13.0.3.1

External References

Related Security Bulletins