Race condition in IBM Java SDK - CVE-2024-27267

 

Race condition in IBM Java SDK - CVE-2024-27267

Published: September 12, 2024


Vulnerability identifier: #VU97226
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27267
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a race condition in ORB listener. A remote attacker can trigger a race condition and perform a denial of service (DoS) attack.


Affected software

IBM Java SDK
Rational Business Developer (RBD)
IBM App Connect Enterprise
IBM SPSS Collaboration and Deployment Services
IBM Tivoli Monitoring
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Sterling Connect:Direct Web Services
IBM Tivoli Netcool Impact
IBM Spectrum Symphony
IBM TXSeries for Multiplatforms
WebSphere Service Registry and Repository
WebSphere eXtreme Scale
IBM Common Licensing
IBM Sterling Transformation Extender
IBM SPSS Modeler
IBM Cloud Application Business Insights
Financial Transaction Manager for Digital Payments (DP)
IBM Cloud Transformation Advisor
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Sterling Secure Proxy
IBM Tivoli Business Service Manager
IBM Sterling Control Center
IBM Rational Build Forge
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance - Containerized Identity Manager
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM InfoSphere Information Server
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Enterprise Storage
IBM AIX
IBM i
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Legacy Module
openSUSE Leap
IBM Cloud Pak System
IBM VIOS
IBM WebSphere Application Server
Tivoli Network Manager IP Edition
Informix JDBC Driver
Rational Synergy
Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines
Tivoli Monitoring for Virtual Environments Base
IBM OpenPages with Watson
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
Cognos Transformer
Guardium Data Protection
DB2 Query Management Facility for z/OS
PowerVM NovaLink
IBM Secure External Authentication Server
Tivoli Network Configuration Manager IP Edition
Security Directory Integrator
Storage Protect Operations Center
Storage Protect Server
Security Verify Directory Integrator
Integration Bus for z/OS
Robotic Process Automation for Cloud Pak
Storage Insights - Data Collector
java-1_8_0-ibm
java-1_8_0-ibm-devel
java-1_8_0-ibm-plugin
java-1_8_0-ibm-alsa
java-1_8_0-ibm-32bit
java-1_8_0-ibm-devel-32bit
java-1_8_0-ibm-demo
java-1_8_0-ibm-src
Planning Analytics Local
Financial Transaction Manager
IBM Qradar SIEM
IBM License Metric Tool
IBM Tivoli Application Dependency Discovery Manager
IBM App Connect Professional
Informix Dynamic Server
IBM Security SOAR

How to mitigate CVE-2024-27267

Install updates from vendor's website.

IBM Java SDK - addressed in versions 7.1.5.23, 8.0.8.30
IBM Cloud Pak System - update to 2.3.4.1 iFix 1
Tivoli Network Manager IP Edition - update to 4.2.0.20
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.26, 6.2.0.25, 6.3.0.10
IBM Tivoli Netcool Impact - update to 7.1.0.35
Rational Synergy - update to 7.2.2.7
IBM Spectrum Symphony - update to 7.3.2 FP3
WebSphere eXtreme Scale - update to 8.6.1.6 PH63791 iFix
Cognos Transformer - addressed in versions 11.2.4 FP 6, 12.0.4 FP 1
IBM Cloud Application Business Insights - addressed in versions 1.1.7.10, 1.1.8.5
java-1_8_0-ibm - addressed in versions 1.8.0_sr8.30-30.126.1, 1.8.0_sr8.30-150000.3.92.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr8.30-30.126.1, 1.8.0_sr8.30-150000.3.92.1
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr8.30-30.126.1, 1.8.0_sr8.30-150000.3.92.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr8.30-30.126.1, 1.8.0_sr8.30-150000.3.92.1
java-1_8_0-ibm-32bit - update to 1.8.0_sr8.30-150000.3.92.1
java-1_8_0-ibm-devel-32bit - update to 1.8.0_sr8.30-150000.3.92.1
java-1_8_0-ibm-demo - update to 1.8.0_sr8.30-150000.3.92.1
java-1_8_0-ibm-src - update to 1.8.0_sr8.30-150000.3.92.1
Planning Analytics Local - addressed in versions 2.0.0.101, 2.0.9.21, 2.1.8
PowerVM NovaLink - addressed in versions 2.1.1-240913, 2.2.1-240917
Financial Transaction Manager for Digital Payments (DP) - update to 3.2.13
IBM Cloud Transformation Advisor - update to 3.10.1
Financial Transaction Manager - update to 4.0.6.0 iFix4
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
IBM Spectrum Control - update to 5.4.13
IBM Sterling Secure Proxy - addressed in versions 6.0.3.1, 6.1.0.1
IBM Secure External Authentication Server - addressed in versions 6.0.3.1 iFix 02, 6.1.0.2 iFix 02
IBM Tivoli Business Service Manager - update to 6.2.0.5.5
IBM Sterling Control Center - addressed in versions 6.2.1.0.14, 6.3.1.0.3
Tivoli Network Configuration Manager IP Edition - update to 6.4.2.21
Security Directory Integrator - update to 7.2.0 LA0033
IBM Tivoli Application Dependency Discovery Manager - update to 7.3.0.11
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
IBM App Connect Professional - update to 7.5.5.0.26
IBM Rational Build Forge - update to 8.0.0.27
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.28
Storage Protect Operations Center - update to 8.1.24
Storage Protect Server - update to 8.1.24
IBM WebSphere Application Server - update to 8.5.5.27
IBM License Metric Tool - update to 9.2.37
Security Verify Directory Integrator - update to 10.0.0 LA0004
Integration Bus for z/OS - update to 10.1.0.4
IBM Security Verify Governance - Containerized Identity Manager - update to 11.0.0.0
IBM App Connect Enterprise - update to 12.0.12.6
Informix Dynamic Server - addressed in versions 12.10.xC16W2, 14.10.xC11
IBM Business Automation Workflow - addressed in versions 21.0.3-IF037, 24.0.0-IF003
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18
IBM Security SOAR - update to 51.0.3.1
Storage Insights - Data Collector - update to 20250116-0048

External References

Related Security Bulletins