Resource exhaustion in IBM WebSphere Application Server Liberty - CVE-2024-27268

 

Resource exhaustion in IBM WebSphere Application Server Liberty - CVE-2024-27268

Published: April 4, 2024 / Updated: August 7, 2024


Vulnerability identifier: #VU88136
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27268
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

IBM WebSphere Application Server Liberty
Jazz Foundation
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Engineering Requirements Management DOORS Next
Engineering Test Management
IBM OpenPages with Watson
Maximo Application Suite - Visual Inspection Component
PowerVM NovaLink
IBM Planning Analytics Workspace
Answer Retrieval for Watson Discovery On Prem
Storage Protect Operations Center
Maximo Application Suite - Monitor Component
Maximo Application Suite - Predict Component
Business Automation Insights
Engineering Workflow Management
Netcool Operations Insight
IBM MQ Operator
IBM SPSS Analytic Server
IBM Sterling B2B Integrator
IBM Tivoli Netcool Impact
IBM Spectrum Symphony
IBM Maximo Application Suite
WebSphere Remote Server
CICS Transaction Gateway
IBM Robotic Process Automation
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Match 360
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Common Licensing
IBM TXSeries for Multiplatforms
IBM MQ
IBM Security Verify Governance - Containerized Identity Manager
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Cloud Pak System
IBM i
IBM Tivoli Application Dependency Discovery Manager
IBM Cognos Controller
Financial Transaction Manager
IBM License Metric Tool
Voice Gateway
Planning Analytics Local
IBM Cognos Analytics
IBM InfoSphere Information Server

How to mitigate CVE-2024-27268

Install updates from vendor's website.

IBM WebSphere Application Server Liberty - update to 24.0.0.5
Netcool Operations Insight - update to 1.6.15
IBM MQ Operator - addressed in versions 9.3.0.20-r1, 9.4.0.0-r2
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM Tivoli Netcool Impact - update to 7.1.0.34
IBM Spectrum Symphony - update to 7.3.2 FP3
Maximo Application Suite - Visual Inspection Component - update to 8.9.20
IBM Maximo Application Suite - addressed in versions 8.10.16, 8.11.13, 9.0.1
IBM Cognos Controller - update to 11.0.1.0.3
IBM Robotic Process Automation - addressed in versions 21.0.7.16, 23.0.17
Voice Gateway - addressed in versions 1.0.8.12, 1.0.8.15
PowerVM NovaLink - addressed in versions 2.0.3.1-240625, 2.1.1-240625, 2.2.1-240626
Planning Analytics Local - update to 2.0.9.20
IBM Planning Analytics Workspace - update to 2.1.4
Answer Retrieval for Watson Discovery On Prem - update to 2.17.0
Financial Transaction Manager - update to 4.0.6.0 iFix4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.6
IBM Match 360 - update to 5.0.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
Storage Protect Operations Center - update to 8.1.24
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.14
Maximo Application Suite - Monitor Component - addressed in versions 8.10.12, 8.11.9, 9.0.0
Maximo Application Suite - Predict Component - update to 9.0.0
IBM Common Licensing - update to 9.0.0.1
IBM TXSeries for Multiplatforms - update to 9.1.0.3
IBM MQ - addressed in versions 9.1.0.22, 9.2.0.26, 9.3.0.20, 9.4
IBM License Metric Tool - update to 9.2.36
IBM CICS TX Advanced - update to 10.1.0.0 ifix28
IBM Security Verify Governance - Containerized Identity Manager - update to 11.0.0.0
IBM CICS TX Standard - update to 11.1.0.0 ifix20
IBM Cognos Analytics - addressed in versions 11.2.4 IF5, 12.0.4 IF2
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
IBM Business Automation Workflow - addressed in versions 21.0.3 IF033, 23.0.2 IF005
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF034, 23.0.2-IF006
Business Automation Insights - update to 23.0.2.0.6

External References

Related Security Bulletins