Input validation error in IBM WebSphere Application Server - CVE-2024-45085

 

Input validation error in IBM WebSphere Application Server - CVE-2024-45085

Published: October 16, 2024


Vulnerability identifier: #VU98730
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45085
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when a JSF application configured with Sun Reference Implementation 1.2. A remote attacker can send  specially crafted requests to the server and perform a denial of service (DoS) attack.


Affected software

IBM WebSphere Application Server
Engineering Test Management
Tivoli Composite Application Manager for Application Diagnostics
Business Monitor
IBM Business Automation Workflow
Jazz for Service Management
IBM Maximo Asset Management
WebSphere Remote Server
InfoSphere Master Data Management
IBM Tivoli Monitoring
IBM Cloud Pak System

How to mitigate CVE-2024-45085

Install updates from vendor's website.

IBM WebSphere Application Server - update to 8.5.5.27
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5

External References

Related Security Bulletins