Resource exhaustion in Jetty - CVE-2025-1948

 

Resource exhaustion in Jetty - CVE-2025-1948

Published: May 9, 2025


Vulnerability identifier: #VU108836
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-1948
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when handling HTTP/2 requests. A remote attacker can force the server to allocate a large amount of resources and perform a denial of service (DoS) attack.


Affected software

Jetty
Netezza Appliance
IBM Cloud Pak for Watson AIOps
Knowledge Catalog Premium Cartridge
IBM Sterling Connect:Direct for Microsoft Windows
watsonx.data
OpenShift Developer Tools and Services
Red Hat Camel for Spring Boot
IBM Watson Knowledge Catalog in Cloud Pak for Data
Oracle Communications EAGLE Element Management System
IBM Sterling Connect:Direct for UNIX
IBM Cognos Command Center
Event Streams
Oracle Banking Origination
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
AMQ Broker

How to mitigate CVE-2025-1948

Install updates from vendor's website.

Jetty - update to 12.0.17
Netezza Appliance - update to 1.0.0.1
watsonx.data - update to 2.2.2
IBM Cloud Pak for Watson AIOps - update to 4.10.0
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
IBM Cognos Command Center - update to 10.2.5 FP1 IF2
Event Streams - update to 12.2.1
jenkins (Red Hat package) - addressed in versions 2.504.2.1750846524-3.el9, 2.504.2.1750851690-3.el9, 2.504.2.1750856366-3.el8, 2.504.2.1750857144-3.el9, 2.504.2.1750903189-3.el8, 2.504.2.1750916374-3.el8, 2.504.2.1750932984-3.el8
Red Hat Camel for Spring Boot - update to 4.10.3
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1750933270-1.el8, 4.13.1750916671-1.el8, 4.14.1750903529-1.el8, 4.15.1750856638-1.el8, 4.16.1750857315-1.el9, 4.17.1750851950-1.el9, 4.18.1750846854-1.el9
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.3.0.6, 6.4.0.3
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.6.6, 6.4.0.3.7
AMQ Broker - update to 7.13.1

External References

Related Security Bulletins