Allocation of Resources Without Limits or Throttling in MongoDB - CVE-2021-32036
Published: March 27, 2024
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote user can repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention to perform a denial of service (DoS) attack.
Affected software
Storage Copy Data Management
IBM Spectrum Protect Plus
How to mitigate CVE-2021-32036
Storage Copy Data Management - update to 2.2.23.0
IBM Spectrum Protect Plus - update to 10.1.6.4