Resource exhaustion in IBM WebSphere Application Server Liberty - CVE-2020-4590
Published: May 2, 2023
Vulnerability identifier: #VU75654
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4590
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM WebSphere Application Server Liberty
IBM Cloud Transformation Advisor
IBM Cloud Application Business Insights
IBM Cloud Transformation Advisor
IBM Cloud Application Business Insights
How to mitigate CVE-2020-4590
Install updates from vendor's website.
IBM WebSphere Application Server Liberty - update to 20.0.0.10
IBM Cloud Application Business Insights - addressed in versions 1.1.3.2, 1.1.4.3, 1.1.5.2
IBM Cloud Application Business Insights - addressed in versions 1.1.3.2, 1.1.4.3, 1.1.5.2