Resource exhaustion in IBM WebSphere Application Server - CVE-2021-38951

 

Resource exhaustion in IBM WebSphere Application Server - CVE-2021-38951

Published: January 6, 2022


Vulnerability identifier: #VU59281
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38951
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can send a specially crafted request to the web server, consume all available CPU resources and perform a denial of service (DoS) attack.


Affected software

IBM WebSphere Application Server
IBM Tivoli Monitoring
InfoSphere Master Data Management
IBM Security Identity Manager Virtual Appliance
IBM Security Directory Server
IBM Security Directory Suite

How to mitigate CVE-2021-38951

Install updates from vendor's website.

IBM Security Directory Server - update to 6.4.0.27
IBM Security Directory Suite - update to 8.0.1.19

External References

Related Security Bulletins