Allocation of Resources Without Limits or Throttling in ion-java - CVE-2024-21634

 

Allocation of Resources Without Limits or Throttling in ion-java - CVE-2024-21634

Published: March 4, 2024 / Updated: December 15, 2025


Vulnerability identifier: #VU86992
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21634
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due in `ion-java` for applications that use `ion-java` to deserialize Ion text encoded data, or deserialize Ion text or binary encoded data into the `IonValue` model and then invoke certain `IonValue` methods on that in-memory representation. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

ion-java
Data Lakehouse
Jira Service Management Data Center
Jira Service Management Server
IBM Sterling B2B Integrator
Confluence Data Center
Bitbucket Data Center
Bamboo Server
Jira Software Data Center
IBM Observability with Instana
Netcool Operations Insight
IBM Fusion HCI
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Maximo Asset Management
IBM Maximo Application Suite - Manage Component
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
DB2 Data Management Console
IBM Application Suite - IBM Asset Data Dictionary Component
Storage Protect Server
Confluence Server
Bitbucket Server
Communications Service Catalog and Design
Jira Software Server
IBM Cognos Controller
eap8-amazon-ion-java (Red Hat package)
eap8-undertow (Red Hat package)
eap8-wildfly (Red Hat package)
eap8-eap-product-conf-parent (Red Hat package)

How to mitigate CVE-2024-21634

Install updates from vendor's website.

ion-java - update to 1.10.5
Data Lakehouse - update to 1.1.0.0
DB2 Data Management Console - update to 3.1.13
Jira Service Management Data Center - addressed in versions 5.4.18, 5.12.6, 5.15.0
Jira Service Management Server - addressed in versions 5.4.18, 5.12.6, 5.15.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.7, 6.2.0.4
Confluence Data Center - addressed in versions 7.19.20, 8.5.7, 8.7.1, 8.8.0
Confluence Server - addressed in versions 7.19.20, 8.5.7, 8.7.1, 8.8.0
Bitbucket Data Center - addressed in versions 7.21.22, 8.9.10, 8.13.6, 8.14.6, 8.15.5, 8.16.3, 8.17.2, 8.18.1
Bitbucket Server - addressed in versions 7.21.22, 8.9.10, 8.13.6, 8.14.5, 8.15.4, 8.16.3, 8.17.2, 8.18.1
Bamboo Server - addressed in versions 9.2.12, 9.4.4, 9.5.2
Jira Software Server - addressed in versions 9.4.18, 9.12.6, 9.15.0
Jira Software Data Center - addressed in versions 9.4.18, 9.12.6, 9.15.0
IBM Cognos Controller - update to 11.0.1.0.3
IBM Observability with Instana - update to 266
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.7
Netcool Operations Insight - update to 1.6.12
eap8-amazon-ion-java (Red Hat package) - addressed in versions 1.11.9-2.redhat_00001.1.el8eap, 1.11.9-2.redhat_00001.1.el9eap
eap8-undertow (Red Hat package) - addressed in versions 2.3.14-2.SP2_redhat_00001.1.el8eap, 2.3.14-2.SP2_redhat_00001.1.el9eap
IBM Fusion HCI - update to 2.8.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0
IBM Maximo Asset Management - update to 7.6.1.3.18
eap8-wildfly (Red Hat package) - addressed in versions 8.0.3-13.GA_redhat_00007.1.el8eap, 8.0.3-13.GA_redhat_00007.1.el9eap
Storage Protect Server - update to 8.1.23
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.13, 8.7.7
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.30, 23.0.2.2
IBM Automation Decision Services - update to 23.0.2.0.2
eap8-eap-product-conf-parent (Red Hat package) - addressed in versions 800.3.1-2.GA_redhat_00002.1.el8eap, 800.3.1-2.GA_redhat_00002.1.el9eap

External References

Related Security Bulletins