Resource exhaustion in Spring Framework - CVE-2024-38808

 

Resource exhaustion in Spring Framework - CVE-2024-38808

Published: August 14, 2024


Vulnerability identifier: #VU96019
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38808
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when evaluating user-supplied SpEL expression. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Spring Framework
IBM Operator for Apache Flink
Enterprise Project Connection
IBM Sterling Partner Engagement Manager
IBM Rational ClearCase
Unified OSS Console Assurance Monitoring (UOCAM)
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Autodesk Infraworks
OpenShift Developer Tools and Services
Red Hat Camel for Spring Boot
IBM Tivoli Netcool Configuration Manager
IBM Business Automation Manager Open Editions
DevOps Code ClearCase
PowerVM NovaLink
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
IBM Tivoli Application Dependency Discovery Manager
Oracle Retail Customer Management and Segmentation Foundation
Planning Analytics Local
watsonx.data
Library Support for Spring
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
HPE Unified OSS Console (UOC)
IBM Qradar SIEM
IBM Cognos Controller
IBM InfoSphere Information Server
IBM Security Guardium

How to mitigate CVE-2024-38808

Install updates from vendor's website.

Spring Framework - update to 5.3.39
IBM Operator for Apache Flink - update to 1.4.5
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.22
IBM Business Automation Manager Open Editions - update to 8.0.7
IBM Rational ClearCase - update to 10.0.1.6
DevOps Code ClearCase - update to 11.0.0.6
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
watsonx.data - update to 2.1
PowerVM NovaLink - addressed in versions 2.1.1-240913, 2.2.1-240917
Library Support for Spring - update to 2.7.29
jenkins (Red Hat package) - addressed in versions 2.462.3.1729837947-3.el8, 2.462.3.1729839727-3.el8, 2.462.3.1729839924-3.el8, 2.462.3.1730119132-3.el8
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.12
HPE Unified OSS Console (UOC) - update to 3.1.12
Red Hat Camel for Spring Boot - update to 4.4.2
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1730119231-1.el8, 4.13.1729840148-1.el8, 4.14.1729839844-1.el8, 4.15.1729838165-1.el8
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
watsonx Assistant Cartridge - update to 5.1.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
IBM Cognos Controller - addressed in versions 11.0.1.4, 11.1.0.2
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
IBM Security Guardium - update to 12.0p30
IBM Business Automation Workflow - addressed in versions 21.0.3-IF039, 24.0.0-IF004
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
Autodesk Infraworks - addressed in versions 2022.1.10.363, 2023.1.5.251, 2024.1.4.152, 2025.02.86

External References

Related Security Bulletins