First published: Wed Apr 24 2024(Updated: )
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 281516.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.4 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
IBM WebSphere Application Server | >=8.5.0.0<=8.5.5.25 | |
IBM WebSphere Application Server | >=9.0.0.0<=9.0.5.19 | |
IBM WebSphere Application Server | >=17.0.0.3<=24.0.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25026 is classified as a denial of service vulnerability that can significantly impact system availability.
To mitigate CVE-2024-25026, update IBM WebSphere Application Server to the latest patched version as provided by IBM.
CVE-2024-25026 affects IBM WebSphere Application Server versions 8.5, 9.0, and Liberty versions 17.0.0.3 through 24.0.0.4.
Yes, CVE-2024-25026 can be exploited remotely by sending specially crafted requests to the server.
CVE-2024-25026 can cause increased resource consumption, potentially leading to service denial.