Resource exhaustion in IBM WebSphere Application Server - CVE-2021-38951
Published: January 6, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can send a specially crafted request to the web server, consume all available CPU resources and perform a denial of service (DoS) attack.
Affected software
IBM Tivoli Monitoring
InfoSphere Master Data Management
IBM Security Identity Manager Virtual Appliance
IBM Security Directory Server
IBM Security Directory Suite
How to mitigate CVE-2021-38951
IBM Security Directory Suite - update to 8.0.1.19
External References
Related Security Bulletins
- Denial of service in IBM WebSphere Application Server
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Denial of service in InfoSphere Master Data Management
- Multiple vulnerabilities in IBM Security Identity Manager Virtual Appliance
- Multiple vulnerabilities in IBM Directory Server and IBM Directory Suite