Resource exhaustion in Jetty - CVE-2025-1948
Published: May 9, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling HTTP/2 requests. A remote attacker can force the server to allocate a large amount of resources and perform a denial of service (DoS) attack.
Affected software
Netezza Appliance
IBM Cloud Pak for Watson AIOps
Knowledge Catalog Premium Cartridge
IBM Sterling Connect:Direct for Microsoft Windows
watsonx.data
OpenShift Developer Tools and Services
Red Hat Camel for Spring Boot
IBM Watson Knowledge Catalog in Cloud Pak for Data
Oracle Communications EAGLE Element Management System
IBM Sterling Connect:Direct for UNIX
IBM Cognos Command Center
Event Streams
Oracle Banking Origination
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
AMQ Broker
How to mitigate CVE-2025-1948
Netezza Appliance - update to 1.0.0.1
watsonx.data - update to 2.2.2
IBM Cloud Pak for Watson AIOps - update to 4.10.0
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
IBM Cognos Command Center - update to 10.2.5 FP1 IF2
Event Streams - update to 12.2.1
jenkins (Red Hat package) - addressed in versions 2.504.2.1750846524-3.el9, 2.504.2.1750851690-3.el9, 2.504.2.1750856366-3.el8, 2.504.2.1750857144-3.el9, 2.504.2.1750903189-3.el8, 2.504.2.1750916374-3.el8, 2.504.2.1750932984-3.el8
Red Hat Camel for Spring Boot - update to 4.10.3
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1750933270-1.el8, 4.13.1750916671-1.el8, 4.14.1750903529-1.el8, 4.15.1750856638-1.el8, 4.16.1750857315-1.el9, 4.17.1750851950-1.el9, 4.18.1750846854-1.el9
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.3.0.6, 6.4.0.3
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.6.6, 6.4.0.3.7
AMQ Broker - update to 7.13.1
External References
Related Security Bulletins
- Remote denial of service in Jetty
- Resource exhaustion in Red Hat Camel for Spring Boot 4.10
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Red Hat Product OCP Tools 4 update for Openshift Jenkins
- Red Hat Product OCPTools 4 update for OpenShift Jenkins
- Red Hat Product OCP Tools 4 update for Openshift Jenkins
- Red Hat Product OCP Tools 4 update for OpenShift Jenkins
- Red Hat Product OCP Tools 4 update for OpenShift Jenkins
- Red Hat Product OCP Tools 4 update for OpenShift Jenkins
- Red Hat Product OCP Tools 4 update for OpenShift Jenkins
- Multiple vulnerabilities in AMQ Broker 7.13
- IBM Sterling Connect:Direct for Microsoft Windows update for Eclipse Jetty
- IBM Sterling Connect:Direct for UNIX update for Eclipse Jetty
- Multiple vulnerabilities in Oracle Communications EAGLE Element Management System
- IBM Netezza Appliance update for Eclipse Jetty
- IBM watsonx.data update for Eclipse Jetty
- Multiple vulnerabilities in IBM Cognos Command Center
- IBM Event Streams update for Eclipse Jetty
- Multiple vulnerabilities in IBM Knowledge Catalog Premium Cartridge
- Multiple vulnerabilities in Oracle Banking Origination
- Multiple vulnerabilities in IBM Watson Knowledge Catalog on-prem