Resource exhaustion in Jetty - CVE-2024-22201
Published: February 26, 2024
Vulnerability identifier: #VU86808
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22201
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling HTTP/2 connections. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Jetty
Rational Functional Tester (RFT)
IBM Observability with Instana
IBM Process Mining
WebSphere Remote Server
Oracle Middleware Common Libraries and Tools
Enterprise Manager Base Platform
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications EAGLE Element Management System
Log Analysis
Netcool Operations Insight
IBM Cloud Pak for Security
IBM MaaS360 Mobile Enterprise Gateway
IBM Sterling Secure Proxy
IBM Sterling Connect:Direct Web Services
IBM MQ
Rational Service Tester
IBM Robotic Process Automation
Integration Bus for z/OS
Cloud Pak for Network Automation
DataStage on Cloud Pak for Data
Oracle Communications ASAP
DevOps
Business Automation Insights
Installation Manager
Packaging Utility
Storage Resource Manager
IBM Secure External Authentication Server
Rational Synergy
Rational Performance Tester
Robotic Process Automation for Cloud Pak
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Development Tools Module
openSUSE Leap
Anolis OS
Jenkins
Jenkins LTS
Oracle Coherence
Dropwizard
watsonx.data
OpenShift Developer Tools and Services
IBM App Connect Enterprise
Rational Change
Oracle Financial Services Compliance Studio
Oracle Retail EFTLink
Oracle AutoVue
Oracle Autovue for Agile Product Lifecycle Management
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Service Communication Proxy
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
jetty-javadoc
jetty-xml
jetty-webapp
jetty-util-ajax
jetty-util
jetty-servlet
jetty-server
jetty-jmx
jetty-jaas
jetty-io
jetty-http
jetty-continuation
jetty-client
jetty-security
jetty
jetty9 (Debian package)
jetty-cdi
jetty-minimal-javadoc
jetty-deploy
jetty-plus
jetty-rewrite
jetty-start
jetty-http-spi
jetty-ant
jetty-quickstart
jetty-jsp
jetty-openid
jetty-annotations
jetty-jndi
jetty-proxy
jetty-servlets
jetty-fcgi
IBM MaaS360 VPN Module
Dell EMC Storage Monitoring and Reporting (SMR)
Rational Functional Tester (RFT)
IBM Observability with Instana
IBM Process Mining
WebSphere Remote Server
Oracle Middleware Common Libraries and Tools
Enterprise Manager Base Platform
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications EAGLE Element Management System
Log Analysis
Netcool Operations Insight
IBM Cloud Pak for Security
IBM MaaS360 Mobile Enterprise Gateway
IBM Sterling Secure Proxy
IBM Sterling Connect:Direct Web Services
IBM MQ
Rational Service Tester
IBM Robotic Process Automation
Integration Bus for z/OS
Cloud Pak for Network Automation
DataStage on Cloud Pak for Data
Oracle Communications ASAP
DevOps
Business Automation Insights
Installation Manager
Packaging Utility
Storage Resource Manager
IBM Secure External Authentication Server
Rational Synergy
Rational Performance Tester
Robotic Process Automation for Cloud Pak
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Development Tools Module
openSUSE Leap
Anolis OS
Jenkins
Jenkins LTS
Oracle Coherence
Dropwizard
watsonx.data
OpenShift Developer Tools and Services
IBM App Connect Enterprise
Rational Change
Oracle Financial Services Compliance Studio
Oracle Retail EFTLink
Oracle AutoVue
Oracle Autovue for Agile Product Lifecycle Management
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Service Communication Proxy
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
jetty-javadoc
jetty-xml
jetty-webapp
jetty-util-ajax
jetty-util
jetty-servlet
jetty-server
jetty-jmx
jetty-jaas
jetty-io
jetty-http
jetty-continuation
jetty-client
jetty-security
jetty
jetty9 (Debian package)
jetty-cdi
jetty-minimal-javadoc
jetty-deploy
jetty-plus
jetty-rewrite
jetty-start
jetty-http-spi
jetty-ant
jetty-quickstart
jetty-jsp
jetty-openid
jetty-annotations
jetty-jndi
jetty-proxy
jetty-servlets
jetty-fcgi
IBM MaaS360 VPN Module
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2024-22201
Install updates from vendor's website.
Jetty - addressed in versions 9.4.54.v20240208, 10.0.20, 11.0.20, 12.0.6
IBM Observability with Instana - update to 1.0.297
IBM Process Mining - update to 1.14.4
Jenkins - update to 2.444
Cloud Pak for Network Automation - update to 2.7.2
Jenkins LTS - update to 2.440.2
Dropwizard - addressed in versions 3.0.7, 4.0.7
DataStage on Cloud Pak for Data - update to 5.2.0
Rational Change - update to 5.3.2.7
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
Log Analysis - update to 1.3.8
Netcool Operations Insight - update to 1.6.12
Installation Manager - update to 1.10.1.1
Packaging Utility - update to 1.10.1.1
IBM Cloud Pak for Security - update to 1.11.2.0
watsonx.data - update to 2.0.2
jenkins (Red Hat package) - addressed in versions 2.440.3.1716387933-3.el8, 2.440.3.1716445150-3.el8, 2.440.3.1716445200-3.el8
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.800
IBM MaaS360 VPN Module - update to 3.000.800
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1716445211-1.el8, 4.13.1716445207-1.el8, 4.14.1716388016-1.el8
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Storage Resource Manager - update to 5.0.1.0
IBM Secure External Authentication Server - addressed in versions 6.0.3.1, 6.1.0.2
IBM Sterling Secure Proxy - addressed in versions 6.0.3.1, 6.1.0.1
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.24, 6.2.0.23, 6.3.0.7
Rational Synergy - update to 7.2.2.7
IBM MQ - addressed in versions 9.0.0.26, 9.1.0.22, 9.2.0.26, 9.4
jetty-javadoc - update to 9.4.43-2
jetty-xml - update to 9.4.43-2
jetty-webapp - update to 9.4.43-2
jetty-util-ajax - update to 9.4.43-2
jetty-util - update to 9.4.43-2
jetty-servlet - update to 9.4.43-2
jetty-server - update to 9.4.43-2
jetty-jmx - update to 9.4.43-2
jetty-jaas - update to 9.4.43-2
jetty-io - update to 9.4.43-2
jetty-http - update to 9.4.43-2
jetty-continuation - update to 9.4.43-2
jetty-client - update to 9.4.43-2
jetty-security - update to 9.4.43-2
jetty - update to 9.4.43-2
jetty9 (Debian package) - addressed in versions 9.4.50-4+deb11u2, 9.4.50-4+deb12u3
jetty-util - update to 9.4.54-150200.3.25.1
jetty-cdi - update to 9.4.54-150200.3.25.1
jetty-io - update to 9.4.54-150200.3.25.1
jetty-util-ajax - update to 9.4.54-150200.3.25.1
jetty-servlet - update to 9.4.54-150200.3.25.1
jetty-server - update to 9.4.54-150200.3.25.1
jetty-minimal-javadoc - update to 9.4.54-150200.3.25.1
jetty-deploy - update to 9.4.54-150200.3.25.1
jetty-jmx - update to 9.4.54-150200.3.25.1
jetty-jaas - update to 9.4.54-150200.3.25.1
jetty-xml - update to 9.4.54-150200.3.25.1
jetty-plus - update to 9.4.54-150200.3.25.1
jetty-rewrite - update to 9.4.54-150200.3.25.1
jetty-start - update to 9.4.54-150200.3.25.1
jetty-webapp - update to 9.4.54-150200.3.25.1
jetty-http-spi - update to 9.4.54-150200.3.25.1
jetty-continuation - update to 9.4.54-150200.3.25.1
jetty-ant - update to 9.4.54-150200.3.25.1
jetty-quickstart - update to 9.4.54-150200.3.25.1
jetty-jsp - update to 9.4.54-150200.3.25.1
jetty-openid - update to 9.4.54-150200.3.25.1
jetty-annotations - update to 9.4.54-150200.3.25.1
jetty-http - update to 9.4.54-150200.3.25.1
jetty-jndi - update to 9.4.54-150200.3.25.1
jetty-proxy - update to 9.4.54-150200.3.25.1
jetty-servlets - update to 9.4.54-150200.3.25.1
jetty-client - update to 9.4.54-150200.3.25.1
jetty-security - update to 9.4.54-150200.3.25.1
jetty-fcgi - update to 9.4.54-150200.3.25.1
IBM App Connect Enterprise - addressed in versions 11.0.0.26, 12.0.12.0
Rational Service Tester - update to 11.0.2
Rational Performance Tester - update to 11.0.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
IBM Observability with Instana - update to 1.0.297
IBM Process Mining - update to 1.14.4
Jenkins - update to 2.444
Cloud Pak for Network Automation - update to 2.7.2
Jenkins LTS - update to 2.440.2
Dropwizard - addressed in versions 3.0.7, 4.0.7
DataStage on Cloud Pak for Data - update to 5.2.0
Rational Change - update to 5.3.2.7
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
Log Analysis - update to 1.3.8
Netcool Operations Insight - update to 1.6.12
Installation Manager - update to 1.10.1.1
Packaging Utility - update to 1.10.1.1
IBM Cloud Pak for Security - update to 1.11.2.0
watsonx.data - update to 2.0.2
jenkins (Red Hat package) - addressed in versions 2.440.3.1716387933-3.el8, 2.440.3.1716445150-3.el8, 2.440.3.1716445200-3.el8
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.800
IBM MaaS360 VPN Module - update to 3.000.800
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1716445211-1.el8, 4.13.1716445207-1.el8, 4.14.1716388016-1.el8
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Storage Resource Manager - update to 5.0.1.0
IBM Secure External Authentication Server - addressed in versions 6.0.3.1, 6.1.0.2
IBM Sterling Secure Proxy - addressed in versions 6.0.3.1, 6.1.0.1
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.24, 6.2.0.23, 6.3.0.7
Rational Synergy - update to 7.2.2.7
IBM MQ - addressed in versions 9.0.0.26, 9.1.0.22, 9.2.0.26, 9.4
jetty-javadoc - update to 9.4.43-2
jetty-xml - update to 9.4.43-2
jetty-webapp - update to 9.4.43-2
jetty-util-ajax - update to 9.4.43-2
jetty-util - update to 9.4.43-2
jetty-servlet - update to 9.4.43-2
jetty-server - update to 9.4.43-2
jetty-jmx - update to 9.4.43-2
jetty-jaas - update to 9.4.43-2
jetty-io - update to 9.4.43-2
jetty-http - update to 9.4.43-2
jetty-continuation - update to 9.4.43-2
jetty-client - update to 9.4.43-2
jetty-security - update to 9.4.43-2
jetty - update to 9.4.43-2
jetty9 (Debian package) - addressed in versions 9.4.50-4+deb11u2, 9.4.50-4+deb12u3
jetty-util - update to 9.4.54-150200.3.25.1
jetty-cdi - update to 9.4.54-150200.3.25.1
jetty-io - update to 9.4.54-150200.3.25.1
jetty-util-ajax - update to 9.4.54-150200.3.25.1
jetty-servlet - update to 9.4.54-150200.3.25.1
jetty-server - update to 9.4.54-150200.3.25.1
jetty-minimal-javadoc - update to 9.4.54-150200.3.25.1
jetty-deploy - update to 9.4.54-150200.3.25.1
jetty-jmx - update to 9.4.54-150200.3.25.1
jetty-jaas - update to 9.4.54-150200.3.25.1
jetty-xml - update to 9.4.54-150200.3.25.1
jetty-plus - update to 9.4.54-150200.3.25.1
jetty-rewrite - update to 9.4.54-150200.3.25.1
jetty-start - update to 9.4.54-150200.3.25.1
jetty-webapp - update to 9.4.54-150200.3.25.1
jetty-http-spi - update to 9.4.54-150200.3.25.1
jetty-continuation - update to 9.4.54-150200.3.25.1
jetty-ant - update to 9.4.54-150200.3.25.1
jetty-quickstart - update to 9.4.54-150200.3.25.1
jetty-jsp - update to 9.4.54-150200.3.25.1
jetty-openid - update to 9.4.54-150200.3.25.1
jetty-annotations - update to 9.4.54-150200.3.25.1
jetty-http - update to 9.4.54-150200.3.25.1
jetty-jndi - update to 9.4.54-150200.3.25.1
jetty-proxy - update to 9.4.54-150200.3.25.1
jetty-servlets - update to 9.4.54-150200.3.25.1
jetty-client - update to 9.4.54-150200.3.25.1
jetty-security - update to 9.4.54-150200.3.25.1
jetty-fcgi - update to 9.4.54-150200.3.25.1
IBM App Connect Enterprise - addressed in versions 11.0.0.26, 12.0.12.0
Rational Service Tester - update to 11.0.2
Rational Performance Tester - update to 11.0.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
External References
Related Security Bulletins
- Remote denial of service in Eclipse Jetty
- Dropwizard update for Jetty
- SUSE update for jetty-minimal
- Denial of service in Jenkins and LTS
- Resource exhaustion in IBM Process Mining
- Multiple vulnerabilities in Netcool Operations Insight
- Resource exhaustion IN IBM Rational Functional Tester/ IBM DevOps Test UI
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Resource exhaustion in IBM App Connect Enterprise and IBM Integration Bus for z/OS
- Multiple vulnerabilities in IBM Log Analysis
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Resource exhaustion in IBM Sterling Connect:Direct Web Services
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender Mobile Enterprise Gateway (MEG) and VPN Module
- Red Hat Product OCP Tools 4.14. Red Hat Product Security has rated this update as having a security impact of Important update for Openshift Jenkins
- Red Hat Product OCP Tools 4.12. Red Hat Product Security has rated this update as having a security impact of Important update for OpenShift Jenkins
- Red Hat Product OCP Tools 4.13. Red Hat Product Security has rated this update as having a security impact of Important update for OpenShift Jenkins
- Resource exhaustion in IBM MQ
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Debian update for jetty9
- Multiple vulnerabilities in Oracle Communications EAGLE Element Management System
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in Oracle Coherence
- Multiple vulnerabilities in Oracle Financial Services Compliance Studio
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Resource exhaustion in Rational Service Tester
- Resource exhaustion in Rational Performance Tester
- Resource exhaustion in IBM watsonx.data
- Multiple vulnerabilities in IBM Rational Change
- Multiple vulnerabilities in IBM Rational Synergy
- Multiple vulnerabilities in IBM Robotic Process Automation
- Resource exhaustion in Oracle Communications ASAP
- Multiple vulnerabilities in Oracle Middleware Common Libraries and Tools
- Multiple vulnerabilities in Enterprise Manager Base Platform
- Multiple vulnerabilities in Oracle Autovue for Agile Product Lifecycle Management
- Multiple vulnerabilities in Oracle Retail EFTLink
- Multiple vulnerabilities in IBM Secure External Authentication Server
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- Anolis OS update for jetty
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in IBM Installation Manager and IBM Packaging Utility
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- IBM DataStage on Cloud Pak for Data update for Jetty package
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in Oracle AutoVue