Input validation error in expat - CVE-2024-50602
Published: November 1, 2024 / Updated: May 20, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the XML_ResumeParser function. A remote attacker can pass specially crafted XML input to the application and perform a denial of service (DoS) attack.
Affected software
IBM Application Gateway
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
OpenBSD
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
Ubuntu
Slackware Linux
Desktop Applications Module
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
openEuler
Fedora
Submariner
IBM Concert Software
IBM OmniFind Text Search Server for DB2 for i
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Security Verify Governance
IBM Power Hardware Management Console (HMC)
IBM Netezza Analytics for NPS
Oracle HTTP Server
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Binding Support Function
Service Interconnect
Multicluster GlobalHub
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
App Connect Enterprise Certified Container
APEX Cloud Platform for Microsoft Azure
Guardium Data Security Center (GDSC)
IBM Cloud Pak for Watson AIOps
IBM Enterprise Content Management Text Search
IBM OpenPages with Watson
IBM Engineering Requirements Management DOORS Next
Verify Identity Access Digital Credentials
Oracle Communications User Data Repository
Cognos Dashboards on Cloud Pak for Data
SmartFabric Manager
iDRAC9
Nessus Network Monitor
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Communications Unified Assurance
LANTIME Operating System Firmware (LTOS)
Precision 7920 Rack
Precision 7920 XL Rack
Dell EMC VxRail Appliance
Oracle Outside In Technology
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libexpat1 (Ubuntu package)
expat (Ubuntu package)
libexpat1-dev (Ubuntu package)
lib64expat1 (Ubuntu package)
lib64expat1-dev (Ubuntu package)
libexpat1-debuginfo-32bit
expat-debuginfo
expat-debuginfo-32bit
libexpat1-debuginfo
expat-debugsource
libexpat1
expat
libexpat1-32bit
expat-devel
expat (Red Hat package)
expat-help
libexpat-devel
libexpat-devel-64bit
libexpat1-64bit-debuginfo
libexpat1-64bit
libexpat1-32bit-debuginfo
expat-32bit-debuginfo
libexpat-devel-32bit
expat-64bit-debuginfo
expat-doc
expat-static
mingw-expat
python3
python311-wxPython-lang
python311-wxPython-debugsource
python311-wxPython-debuginfo
python311-wxPython
python3-wxPython-lang
python3-wxPython-debuginfo
python3-wxPython
python3-wxPython-debugsource
mozjs52
mozjs52-devel
mozjs52-debugsource
libmozjs-52-debuginfo
libmozjs-52
mozjs52-debuginfo
libmozjs-60-debuginfo
mozjs60-devel
mozjs60-debuginfo
mozjs60
libmozjs-60
mozjs60-debugsource
libmozjs-78-0-debuginfo
mozjs78-debuginfo
mozjs78
mozjs78-debugsource
mozjs78-devel
libmozjs-78-0
libmozjs-115-0-debuginfo
libmozjs-115-0
mozjs115-debuginfo
mozjs115-debugsource
mozjs115-devel
mozjs115
IBM Security Verify Access
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Unified Data Repository
OpenShift API for Data Protection (OADP)
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM FileNet Content Manager
Juniper Secure Analytics (JSA)
IBM CICS TX Advanced
How to mitigate CVE-2024-50602
Submariner - addressed in versions 0.16.8, 0.17.6
APEX Cloud Platform for Microsoft Azure - update to 01.04.00.00
IBM Concert Software - update to 1.0.5
SmartFabric Manager - update to 1.2.0
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0
Nessus Network Monitor - update to 6.5.1
LANTIME Operating System Firmware (LTOS) - update to 7.08.018
Dell EMC VxRail Appliance - update to 8.321
IBM OpenPages with Watson - update to 9.1.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
IBM Security Verify Governance - update to 10.0.2.0.5
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP3, 10.3.1060.0 SP1
IBM Netezza Analytics for NPS - update to 11.2.30
libexpat1 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.2.9-1ubuntu0.8, 2.4.7-1ubuntu0.5, 2.6.1-2ubuntu0.2, 2.6.2-2ubuntu0.1
expat (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), lib64expat1, 2.2.9-1ubuntu0.8, 2.4.7-1ubuntu0.5, 2.6.1-2ubuntu0.2, 2.6.2-2ubuntu0.1
libexpat1-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 2.2.9-1ubuntu0.8, 2.4.7-1ubuntu0.5, 2.6.1-2ubuntu0.2, 2.6.2-2ubuntu0.1
lib64expat1 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
lib64expat1-dev (Ubuntu package) - addressed in versions Ubuntu Pro, libexpat1
Service Interconnect - addressed in versions 1, 1.4
Multicluster GlobalHub - update to 1.2.1
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.4, 1.4.2
Migration Toolkit for Containers - update to 1.8.5
libexpat1-debuginfo-32bit - update to 2.1.0-21.40.1
expat-debuginfo - addressed in versions 2.1.0-21.40.1, 2.2.5-150000.3.33.1, 2.4.4-150400.3.25.1
expat-debuginfo-32bit - update to 2.1.0-21.40.1
libexpat1-debuginfo - addressed in versions 2.1.0-21.40.1, 2.2.5-150000.3.33.1, 2.4.4-150400.3.25.1
expat-debugsource - addressed in versions 2.1.0-21.40.1, 2.2.5-150000.3.33.1, 2.4.4-150400.3.25.1
libexpat1 - addressed in versions 2.1.0-21.40.1, 2.2.5-150000.3.33.1, 2.4.4-150400.3.25.1
expat - addressed in versions 2.1.0-21.40.1, 2.4.4-150400.3.25.1
libexpat1-32bit - addressed in versions 2.1.0-21.40.1, 2.4.4-150400.3.25.1
expat-devel - addressed in versions 2.2.5-16, 2.5.0-4
expat - addressed in versions 2.2.5-16, 2.5.0-4
expat (Red Hat package) - addressed in versions 2.2.5-16.el8_10, 2.5.0-1.el9_2.2, 2.5.0-2.el9_4.2, 2.5.0-3.el9_5.1
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.4.7, 2.5.8, 2.6.4
expat - update to 2.4.1-13
expat-debuginfo - update to 2.4.1-13
expat-help - update to 2.4.1-13
expat-devel - update to 2.4.1-13
expat-debugsource - update to 2.4.1-13
libexpat-devel - update to 2.4.4-150400.3.25.1
libexpat-devel-64bit - update to 2.4.4-150400.3.25.1
libexpat1-64bit-debuginfo - update to 2.4.4-150400.3.25.1
libexpat1-64bit - update to 2.4.4-150400.3.25.1
libexpat1-32bit-debuginfo - update to 2.4.4-150400.3.25.1
expat-32bit-debuginfo - update to 2.4.4-150400.3.25.1
libexpat-devel-32bit - update to 2.4.4-150400.3.25.1
expat-64bit-debuginfo - update to 2.4.4-150400.3.25.1
OpenShift Service Mesh - addressed in versions 2.4.13, 2.5.7
expat-doc - update to 2.5.0-4
expat-static - update to 2.5.0-4
mingw-expat - addressed in versions 2.6.3-2.fc39, 2.6.3-2.fc40, 2.6.3-2.fc41, 2.6.4-1.fc40, 2.6.4-1.fc41
expat - update to 2.6.4
expat - addressed in versions 2.6.4-1.fc40, 2.6.4-1.fc41
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.8, 2.9.6, 2.10.7, 2.11.4, 2.12.1
python3 - update to 3.9.21
Red Hat OpenShift Dev Spaces - update to 3.17.0
python311-wxPython-lang - update to 4.1.1-150400.3.8.1
python311-wxPython-debugsource - update to 4.1.1-150400.3.8.1
python311-wxPython-debuginfo - update to 4.1.1-150400.3.8.1
python311-wxPython - update to 4.1.1-150400.3.8.1
python3-wxPython-lang - update to 4.1.1-150400.10.1
python3-wxPython-debuginfo - update to 4.1.1-150400.10.1
python3-wxPython - update to 4.1.1-150400.10.1
python3-wxPython-debugsource - update to 4.1.1-150400.10.1
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.7, 4.5.5
Red Hat OpenShift Container Platform - addressed in versions 4.12.75, 4.13.57, 4.14.41, 4.14.50, 4.15.39, 4.15.49, 4.16.44
OpenShift Virtualization - addressed in versions 4.13.11, 4.17.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.14.13, 4.15.9, 4.16.4, 4.17.1
Cognos Dashboards on Cloud Pak for Data - update to 5.1.1
IBM FileNet Content Manager - addressed in versions 5.5.12.0 IF007, 5.6.0.0 IF006, 5.7.0.0 IF003
OpenShift Logging - addressed in versions 5.6.27, 5.8.16, 5.9.10
iDRAC9 - addressed in versions 7.00.00.181, 7.20.30.50
Precision 7920 Rack - update to 7.00.00.181
Precision 7920 XL Rack - update to 7.00.00.181
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
App Connect Enterprise Certified Container - update to 12.8.0
mozjs52 - update to 52.6.0-150000.3.9.1
mozjs52-devel - update to 52.6.0-150000.3.9.1
mozjs52-debugsource - update to 52.6.0-150000.3.9.1
libmozjs-52-debuginfo - update to 52.6.0-150000.3.9.1
libmozjs-52 - update to 52.6.0-150000.3.9.1
mozjs52-debuginfo - update to 52.6.0-150000.3.9.1
libmozjs-60-debuginfo - update to 60.9.0-150200.6.8.1
mozjs60-devel - update to 60.9.0-150200.6.8.1
mozjs60-debuginfo - update to 60.9.0-150200.6.8.1
mozjs60 - update to 60.9.0-150200.6.8.1
libmozjs-60 - update to 60.9.0-150200.6.8.1
mozjs60-debugsource - update to 60.9.0-150200.6.8.1
libmozjs-78-0-debuginfo - update to 78.15.0-150400.3.11.1
mozjs78-debuginfo - update to 78.15.0-150400.3.11.1
mozjs78 - update to 78.15.0-150400.3.11.1
mozjs78-debugsource - update to 78.15.0-150400.3.11.1
mozjs78-devel - update to 78.15.0-150400.3.11.1
libmozjs-78-0 - update to 78.15.0-150400.3.11.1
libmozjs-115-0-debuginfo - update to 115.4.0-150600.3.6.1
libmozjs-115-0 - update to 115.4.0-150600.3.6.1
mozjs115-debuginfo - update to 115.4.0-150600.3.6.1
mozjs115-debugsource - update to 115.4.0-150600.3.6.1
mozjs115-devel - update to 115.4.0-150600.3.6.1
mozjs115 - update to 115.4.0-150600.3.6.1
External References
Related Security Bulletins
- Denial of service in expat
- openEuler update for expat
- Fedora 39 update for mingw-expat
- Fedora 41 update for mingw-expat
- Fedora 40 update for mingw-expat
- Slackware Linux update for expat
- Fedora 41 update for mingw-expat
- Fedora 40 update for mingw-expat
- SUSE update for python-wxPython
- Fedora 41 update for expat
- Fedora 40 update for expat
- SUSE update for expat
- SUSE update for expat
- Red Hat Enterprise Linux 8 update for expat
- Red Hat Enterprise Linux 9 update for expat
- OpenBSD update for libexpat
- SUSE update for python3-wxPython
- SUSE update for expat
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Service Interconnect 1
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.3
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.8
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Slackware Linux update for python3
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Ubuntu update for expat
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.17
- Multiple vulnerabilities in Service Interconnect
- Red Hat Enterprise Linux 9 update for expat
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.16
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- SUSE update for mozjs78
- Multiple vulnerabilities in OpenShift Virtualization 4.17
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in OpenShift Logging 5.9
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Unified Data Repository
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.9
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.5
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.4
- Multiple vulnerabilities in Submariner
- Multiple vulnerabilities in Multicluster GlobalHub 1.2
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- IBM Power Hardware Management Console (HMC) update for libexpat
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Dell SmartFabric Manager update for third-party components
- Multiple vulnerabilities in IBM Concert Software
- Red Hat Enterprise Linux 9 update for expat
- Anolis OS update for expat
- Dell VxRail Appliance 8.x update for third-party components
- APEX Cloud Platform for Microsoft Azure update for third-party components
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Multiple vulnerabilities in Oracle Communications User Data Repository
- Multiple vulnerabilities in Oracle Communications Network Analytics Data Director
- Multiple vulnerabilities in Oracle Outside In Technology
- Multiple vulnerabilities in Oracle HTTP Server
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in IBM CICS TX Advanced
- Juniper Secure Analytics update for third-party components
- Meinberg LANTIME firmware update for third-party components (December 2024)
- Multiple vulnerabilities in Dell iDRAC9
- Multiple vulnerabilities in Dell Precision Rack
- Multiple vulnerabilities in Tenable Network Monitor
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Submariner 0.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM Security Guardium Key Lifecycle Manager
- Anolis OS update for expat
- Multiple vulnerabilities in IBM OpenPages
- Multiple vulnerabilities in IBM Application Gateway
- SUSE update for mozjs52
- Multiple vulnerabilities in IBM Verify Identity Access and IBM Security Verify Access
- SUSE update for mozjs60
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS and DOORS Web Access
- Multiple vulnerabilities in IBM FileNet Content Manager (FNCM) Content Based Retrieval (CBR)
- Multiple vulnerabilities in IBM Netezza Analytics for NPS
- Multiple vulnerabilities in IBM OmniFind Text Search Server for DB2 for i
- SUSE update for mozjs115