Allocation of Resources Without Limits or Throttling in IBM WebSphere Application Server - CVE-2019-4720
Published: June 14, 2023
Vulnerability identifier: #VU77313
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-4720
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can send a specially-crafted request, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM WebSphere Application Server
IBM Cloud Transformation Advisor
IBM Cloud Application Business Insights
IBM CICS TX on Cloud
Watson Speech to Text Customer Care
IBM Cloud Transformation Advisor
IBM Cloud Application Business Insights
IBM CICS TX on Cloud
Watson Speech to Text Customer Care
How to mitigate CVE-2019-4720
Install updates from vendor's website.
IBM Cloud Transformation Advisor - update to 2.0.3
Watson Speech to Text Customer Care - update to 1.1.2
IBM Cloud Application Business Insights - addressed in versions 1.1.3.1, 1.1.4.2
IBM CICS TX on Cloud - update to 10.1.0.0 SpecialFIX 032020
Watson Speech to Text Customer Care - update to 1.1.2
IBM Cloud Application Business Insights - addressed in versions 1.1.3.1, 1.1.4.2
IBM CICS TX on Cloud - update to 10.1.0.0 SpecialFIX 032020
External References
Related Security Bulletins
- Allocation of resources without limits or throttling in IBM Cloud Transformation Advisor
- Allocation of resources without limits or throttling in IBM Watson Speech to Text Customer Care
- Allocation of resources without limits or throttling in IBM CICS TX on Cloud
- Multiple vulnerabilities in IBM Cloud Application Business Insights