Input validation error in IBM WebSphere Application Server - CVE-2024-45085
Published: October 16, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when a JSF application configured with Sun Reference Implementation 1.2. A remote attacker can send specially crafted requests to the server and perform a denial of service (DoS) attack.
Affected software
Engineering Test Management
Tivoli Composite Application Manager for Application Diagnostics
Business Monitor
IBM Business Automation Workflow
Jazz for Service Management
IBM Maximo Asset Management
WebSphere Remote Server
InfoSphere Master Data Management
IBM Tivoli Monitoring
IBM Cloud Pak System
How to mitigate CVE-2024-45085
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
External References
Related Security Bulletins
- Denial of service in IBM WebSphere Application Server
- IBM Jazz for Service Management update for IBM WebSphere Application Server
- IBM Master Data Management update for IBM WebSphere Application Server
- Input validation error in IBM WebSphere Application Server
- Input validation error in IBM Tivoli Composite Application Manager for Application Diagnostics
- Multiple vulnerabilities in IBM Business Automation Workflow
- Input validation error in IBM Maximo Asset Management
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Multiple vulnerabilities in IBM Business Monitor
- Input validation error in IBM Engineering Test Management
- Multiple vulnerabilities in IBM Cloud Pak System