Resource exhaustion in vCenter Server - CVE-2024-37087
Published: June 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the License Server. A remote attacker can send specially crafted packets to the server, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
PowerStore X
PowerProtect DP Series Appliance (IDPA)
IBM Cloud Pak System
How to mitigate CVE-2024-37087
IBM Cloud Pak System - update to 2.3.4.1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7