Resource exhaustion in IBM WebSphere Application Server - CVE-2024-22353
Published: April 4, 2024 / Updated: October 22, 2024
Vulnerability identifier: #VU88123
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22353
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM WebSphere Application Server
IBM WebSphere Application Server Liberty
Engineering Workflow Management
IBM MQ Operator
IBM SPSS Analytic Server
IBM Sterling B2B Integrator
IBM Tivoli Netcool Impact
IBM Maximo Application Suite
WebSphere Remote Server
IBM Match 360
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite - Manage Component
IBM TXSeries for Multiplatforms
IBM MQ
IBM Security Verify Governance - Containerized Identity Manager
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
Engineering Test Management
IBM Engineering Requirements Management DOORS Next
IBM OpenPages with Watson
PowerVM NovaLink
IBM Planning Analytics Workspace
Maximo Application Suite - Monitor Component
Maximo Application Suite - Predict Component
Robotic Process Automation for Cloud Pak
Business Automation Insights
Jazz Foundation
IBM CICS TX Advanced
IBM CICS TX Standard
IBM i
IBM Cognos Controller
Financial Transaction Manager
IBM License Metric Tool
Planning Analytics Local
IBM Cognos Analytics
IBM WebSphere Application Server Liberty
Engineering Workflow Management
IBM MQ Operator
IBM SPSS Analytic Server
IBM Sterling B2B Integrator
IBM Tivoli Netcool Impact
IBM Maximo Application Suite
WebSphere Remote Server
IBM Match 360
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite - Manage Component
IBM TXSeries for Multiplatforms
IBM MQ
IBM Security Verify Governance - Containerized Identity Manager
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
Engineering Test Management
IBM Engineering Requirements Management DOORS Next
IBM OpenPages with Watson
PowerVM NovaLink
IBM Planning Analytics Workspace
Maximo Application Suite - Monitor Component
Maximo Application Suite - Predict Component
Robotic Process Automation for Cloud Pak
Business Automation Insights
Jazz Foundation
IBM CICS TX Advanced
IBM CICS TX Standard
IBM i
IBM Cognos Controller
Financial Transaction Manager
IBM License Metric Tool
Planning Analytics Local
IBM Cognos Analytics
How to mitigate CVE-2024-22353
Install updates from vendor's website.
IBM MQ Operator - addressed in versions 9.3.0.20-r1, 9.4.0.0-r2
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM Tivoli Netcool Impact - update to 7.1.0.34
IBM Maximo Application Suite - addressed in versions 8.10.16, 8.11.13, 9.0.1
IBM Cognos Controller - update to 11.0.1.0.3
PowerVM NovaLink - addressed in versions 2.0.3.1-240625, 2.1.1-240625, 2.2.1-240626
Planning Analytics Local - update to 2.0.9.20
IBM Planning Analytics Workspace - update to 2.1.4
Financial Transaction Manager - update to 4.0.6.0 iFix4
IBM Match 360 - update to 5.0.1
IBM Spectrum Control - update to 5.4.12
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.14
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.17, 8.7.11
Maximo Application Suite - Monitor Component - addressed in versions 8.10.12, 8.11.9, 9.0.0
Maximo Application Suite - Predict Component - update to 9.0.0
IBM TXSeries for Multiplatforms - update to 9.1.0.3
IBM MQ - addressed in versions 9.1.0.22, 9.2.0.26, 9.3.0.20, 9.4
IBM License Metric Tool - update to 9.2.36
IBM Security Verify Governance - Containerized Identity Manager - update to 10.0.2
IBM CICS TX Advanced - update to 10.1.0.0 ifix28
IBM CICS TX Standard - update to 11.1.0.0 ifix20
IBM Cognos Analytics - addressed in versions 11.2.4 IF5, 12.0.4 IF2
IBM Business Automation Workflow - addressed in versions 21.0.3 IF033, 23.0.2 IF005
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 21.0.3.32, 23.0.2.4, 24.0.0-IF001
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
Business Automation Insights - update to 23.0.2.0.6
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM Tivoli Netcool Impact - update to 7.1.0.34
IBM Maximo Application Suite - addressed in versions 8.10.16, 8.11.13, 9.0.1
IBM Cognos Controller - update to 11.0.1.0.3
PowerVM NovaLink - addressed in versions 2.0.3.1-240625, 2.1.1-240625, 2.2.1-240626
Planning Analytics Local - update to 2.0.9.20
IBM Planning Analytics Workspace - update to 2.1.4
Financial Transaction Manager - update to 4.0.6.0 iFix4
IBM Match 360 - update to 5.0.1
IBM Spectrum Control - update to 5.4.12
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.14
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.17, 8.7.11
Maximo Application Suite - Monitor Component - addressed in versions 8.10.12, 8.11.9, 9.0.0
Maximo Application Suite - Predict Component - update to 9.0.0
IBM TXSeries for Multiplatforms - update to 9.1.0.3
IBM MQ - addressed in versions 9.1.0.22, 9.2.0.26, 9.3.0.20, 9.4
IBM License Metric Tool - update to 9.2.36
IBM Security Verify Governance - Containerized Identity Manager - update to 10.0.2
IBM CICS TX Advanced - update to 10.1.0.0 ifix28
IBM CICS TX Standard - update to 11.1.0.0 ifix20
IBM Cognos Analytics - addressed in versions 11.2.4 IF5, 12.0.4 IF2
IBM Business Automation Workflow - addressed in versions 21.0.3 IF033, 23.0.2 IF005
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 21.0.3.32, 23.0.2.4, 24.0.0-IF001
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
Business Automation Insights - update to 23.0.2.0.6
External References
Related Security Bulletins
- Resource exhaustion in IBM WebSphere Application Server Liberty
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Resource exhaustion in IBM Engineering Lifecycle Engineering product
- Resource exhaustion in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM i
- Multiple vulnerabilities in IBM License Metric Tool
- Multiple vulnerabilities in IBM MQ
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Resource exhaustion in IBM Tivoli Netcool Impact
- Resource exhaustion in IBM PowerVM Novalink
- Resource exhaustion in IBM Maximo Application Suite - Predict Component
- Multiple vulnerabilities in IBM TXSeries for Multiplatforms
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- IBM Maximo Application Suite update for WebSphere Application Server
- Multiple vulnerabilities in IBM Maximo Application Suite - Monitor Component
- Multiple vulnerabilities in IBM OpenPages with Watson
- Multiple vulnerabilities in IBM Spectrum Control
- Multiple vulnerabilities in Planning Analytics Local
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM Security Verify Governance - Containerized Identity Manager
- Resource exhaustion in IBM Match 360
- Resource exhaustion in IBM Maximo Application Suite - Manage Component
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Resource exhaustion in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in IBM Robotic Process Automation
- IBM Sterling B2B Integrator update for WebSphere Application Server
- Multiple vulnerabilities in IBM SPSS Analytic Server
- Multiple vulnerabilities in IBM Financial Transaction Manager (FTM) for Red Hat OpenShift
- Multiple vulnerabilities in IBM Cognos Controller
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in IBM Cloud Application Performance Management (APM)
- Multiple vulnerabilities in IBM MQ Operator