CVE-2024-23081: Null Pointer Dereference
ThreeTen Backport is vulnerable to a denial of service, caused by a NullPointerException flaw in the org.threeten.bp.LocalDate::compareTo(ChronoLocalDate) component. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Other sources
ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate).
http://threeten.com https://gist.github.com/LLM4IG/3cc9183dcd887020368a0bafeafec5e3 https://github.com/ThreeTen/threetenbp
— Red Hat
ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23081?
CVE-2024-23081 has a high severity rating due to the potential for a denial of service attack.
How do I fix CVE-2024-23081?
To fix CVE-2024-23081, update IBM Planning Analytics Local - IBM Planning Analytics Workspace to version 2.2 or later.
Which software versions are affected by CVE-2024-23081?
CVE-2024-23081 affects IBM Planning Analytics Local - IBM Planning Analytics Workspace versions up to and including 2.1 and 2.0.
What type of vulnerability is CVE-2024-23081?
CVE-2024-23081 is a denial of service vulnerability caused by a NullPointerException.
Can CVE-2024-23081 be exploited remotely?
Yes, CVE-2024-23081 can be exploited remotely by sending specially crafted requests.