Resource exhaustion in Jetty - CVE-2024-8184

 

Resource exhaustion in Jetty - CVE-2024-8184

Published: October 14, 2024


Vulnerability identifier: #VU98517
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-8184
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within the ThreadLimitHandler.getRemote() function. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Jetty
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
Anolis OS
IBM Integrated Analytics System
Operations Analytics - Log Analysis
Guardium Data Security Center (GDSC)
IBM Business Automation Manager Open Editions
Storage Protect Server
Rational Performance Tester
DevOps Test UI
webMethods BPM
Oracle Data Integrator
Business Automation Insights
Packaging Utility
Installation Manager
watsonx Assistant for IBM Cloud Pak for Data
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
StreamSets Data Collector
DevOps Deploy
Maximo Application Suite - IoT Component
Hybrid Cloud Observability
Netcool Operations Insight
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
Rational Service Tester
Rational Functional Tester (RFT)
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Network Exposure Function
IBM Cloud Pak for Security
IBM Process Mining
IBM Cloud Object Storage Systems
UCD - IBM UrbanCode Deploy
IBM Cloud Application Performance Management (APM)
PowerProtect Data Manager
watsonx.data
EntireX
Orion Platform
AMQ Streams
IBM App Connect Professional
Operational Decision Manager
jetty-webapp
jetty-util-ajax
jetty-xml
jetty-util
jetty-servlet
jetty-security
jetty-server
jetty
jetty-jmx
jetty-javadoc
jetty-jaas
jetty-io
jetty-http
jetty-continuation
jetty-client
jetty-minimal-javadoc
jetty-rewrite
jetty-start
jetty-cdi
jetty-proxy
jetty-openid
jetty-quickstart
jetty-jsp
jetty-plus
jetty-http-spi
jetty-servlets
jetty-ant
jetty-jndi
jetty-fcgi
jetty-deploy
jetty-annotations
jetty9 (Debian package)
Event Streams
IBM InfoSphere Information Server

How to mitigate CVE-2024-8184

Install updates from vendor's website.

Jetty - addressed in versions 9.4.56.v20240826, 10.0.24, 11.0.24, 12.0.9
IBM Integrated Analytics System - update to 1.0.31.0
Operations Analytics - Log Analysis - update to 1.3.8.4
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2.1
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.16, 6.4.0.5
IBM Sterling Control Center - addressed in versions 6.3.1.0.4, 6.4.0.0.1
IBM Business Automation Manager Open Editions - update to 8.0.8
Storage Protect Server - update to 8.2.1
Rational Performance Tester - update to 11.0.7
Rational Service Tester - update to 11.0.7
DevOps Test UI - update to 11.0.7
EntireX - update to 11.1.1
webMethods BPM - update to 11.1 Fix 6
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF005, 24.0.1-IF004, 25.0.0
Orion Platform - update to 2025.4.1
Packaging Utility - update to 1.10.1.1
Installation Manager - update to 1.10.1.1
IBM Cloud Pak for Security - update to 1.11.2.0
IBM Process Mining - update to 1.15.0 IF004
AMQ Streams - update to 2
IBM Cloud Object Storage Systems - addressed in versions 3.18.0.84, 3.18.5.40
watsonx Assistant for IBM Cloud Pak for Data - update to 4.8.8
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
StreamSets Data Collector - update to 7.0.0
UCD - IBM UrbanCode Deploy - addressed in versions 7.0.5.25, 7.1.2.21, 7.2.3.14, 7.3.2.9
IBM App Connect Professional - update to 7.5.5.0.28
DevOps Deploy - addressed in versions 8.0.1.4, 8.1.0.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
Maximo Application Suite - IoT Component - addressed in versions 8.7.19, 8.8.15, 9.0.5
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 42, 8.11.1.0 Interim fix 39, 8.12.0.1 Interim fix 24, 9.0.0.1 Interim fix 7
jetty-webapp - update to 9.4.43-5
jetty-util-ajax - update to 9.4.43-5
jetty-xml - update to 9.4.43-5
jetty-util - update to 9.4.43-5
jetty-servlet - update to 9.4.43-5
jetty-security - update to 9.4.43-5
jetty-server - update to 9.4.43-5
jetty - update to 9.4.43-5
jetty-jmx - update to 9.4.43-5
jetty-javadoc - update to 9.4.43-5
jetty-jaas - update to 9.4.43-5
jetty-io - update to 9.4.43-5
jetty-http - update to 9.4.43-5
jetty-continuation - update to 9.4.43-5
jetty-client - update to 9.4.43-5
jetty-minimal-javadoc - update to 9.4.56-150200.3.28.1
jetty-util-ajax - update to 9.4.56-150200.3.28.1
jetty-rewrite - update to 9.4.56-150200.3.28.1
jetty-start - update to 9.4.56-150200.3.28.1
jetty-cdi - update to 9.4.56-150200.3.28.1
jetty-proxy - update to 9.4.56-150200.3.28.1
jetty-server - update to 9.4.56-150200.3.28.1
jetty-openid - update to 9.4.56-150200.3.28.1
jetty-quickstart - update to 9.4.56-150200.3.28.1
jetty-jsp - update to 9.4.56-150200.3.28.1
jetty-plus - update to 9.4.56-150200.3.28.1
jetty-security - update to 9.4.56-150200.3.28.1
jetty-servlet - update to 9.4.56-150200.3.28.1
jetty-jmx - update to 9.4.56-150200.3.28.1
jetty-util - update to 9.4.56-150200.3.28.1
jetty-webapp - update to 9.4.56-150200.3.28.1
jetty-http-spi - update to 9.4.56-150200.3.28.1
jetty-servlets - update to 9.4.56-150200.3.28.1
jetty-http - update to 9.4.56-150200.3.28.1
jetty-ant - update to 9.4.56-150200.3.28.1
jetty-jaas - update to 9.4.56-150200.3.28.1
jetty-continuation - update to 9.4.56-150200.3.28.1
jetty-jndi - update to 9.4.56-150200.3.28.1
jetty-fcgi - update to 9.4.56-150200.3.28.1
jetty-io - update to 9.4.56-150200.3.28.1
jetty-deploy - update to 9.4.56-150200.3.28.1
jetty-xml - update to 9.4.56-150200.3.28.1
jetty-annotations - update to 9.4.56-150200.3.28.1
jetty-client - update to 9.4.56-150200.3.28.1
jetty9 (Debian package) - update to 9.4.57-0+deb12u1
Event Streams - update to 11.6.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
PowerProtect Data Manager - update to 19.19.0-15
Hybrid Cloud Observability - update to 2025.4.1

External References

Related Security Bulletins