Resource exhaustion in Red Hat build of Quarkus - CVE-2025-1634
Published: April 3, 2025
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists in in the quarkus-resteasy extension due to application does not properly control consumption of internal resources when client requests with low timeouts are made. A remote user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM Automation Decision Services
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
IBM Business Automation Manager Open Editions
Event Streams
AMQ Streams
How to mitigate CVE-2025-1634
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.1.3
IBM Business Automation Manager Open Editions - update to 9.2.1
Event Streams - update to 12.2.1
AMQ Streams - addressed in versions 2, 3.1.0
External References
Related Security Bulletins
- Multiple vulnerabilities in Red Hat build of Quarkus
- Multiple vulnerabilities in AMQ Streams
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- IBM watsonx Orchestrate with watsonx Assistant Cartridge – UAB Component update for quarkus-resteasy
- Multiple vulnerabilities in IBM Automation Decision Services
- Red Hat AMQ Streams update for Apache Kafka
- IBM Event Streams update for quarkus-resteasy extension