Allocation of Resources Without Limits or Throttling in IBM WebSphere Application Server - CVE-2019-4720

 

Allocation of Resources Without Limits or Throttling in IBM WebSphere Application Server - CVE-2019-4720

Published: June 14, 2023


Vulnerability identifier: #VU77313
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-4720
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can send a specially-crafted request, trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

IBM WebSphere Application Server
IBM Cloud Transformation Advisor
IBM Cloud Application Business Insights
IBM CICS TX on Cloud
Watson Speech to Text Customer Care

How to mitigate CVE-2019-4720

Install updates from vendor's website.

IBM Cloud Transformation Advisor - update to 2.0.3
Watson Speech to Text Customer Care - update to 1.1.2
IBM Cloud Application Business Insights - addressed in versions 1.1.3.1, 1.1.4.2
IBM CICS TX on Cloud - update to 10.1.0.0 SpecialFIX 032020

External References

Related Security Bulletins