Infinite loop in Java Runtime Environment - CVE-2009-2625

 

Infinite loop in Java Runtime Environment - CVE-2009-2625

Published: February 27, 2024


Vulnerability identifier: #VU86821
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2009-2625
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop. A remote attacker can send a malformed XML input to the application, consume all available system resources and cause denial of service conditions.


Affected software

Java Runtime Environment
IBM Sterling Order Management
Tivoli Network Manager IP Edition
IBM Engineering Requirements Management DOORS Next
IBM Engineering Systems Design Rhapsody
Call Center for Commerce
IBM Content Navigator
Slackware Linux
IBM SPSS Modeler
Atlas eDiscovery Process Management
Tivoli Composite Application Manager for Transactions
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
expat
Operational Decision Manager

How to mitigate CVE-2009-2625

Install updates from vendor's website.

Java Runtime Environment - addressed in versions 5.0 Update 20, 6.0 Update 15
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008, 3.2.0 IF004
Tivoli Network Manager IP Edition - update to 4.2.0.20
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
expat - update to 2.0.1
Atlas eDiscovery Process Management - update to 6.0.3.9.7
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 36, 8.11.0.1 Interim fix 17, 8.11.0.1 Interim fix 18, 8.11.1 Interim fix 7
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
IBM Security Verify Governance - update to 10.0.2
Call Center for Commerce - update to 10.0.2403.1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF028, 23.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6

External References

Related Security Bulletins