PT-2024-12693 · Ibm+3 · Ibm Sdk+4
Published
2024-05-10
·
Updated
2025-08-14
·
CVE-2023-38264
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
IBM SDK, Java Technology Edition versions 7.1.0.0 through 7.1.5.21
IBM SDK, Java Technology Edition versions 8.0.0.0 through 8.0.8.21
Description
The issue is related to a denial of service attack due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters in the Object Request Broker (ORB). This can occur under certain circumstances.
Recommendations
For versions 7.1.0.0 through 7.1.5.21, update to a version that properly enforces the JEP 290 MaxRef and MaxDepth deserialization filters to prevent denial of service attacks.
For versions 8.0.0.0 through 8.0.8.21, update to a version that properly enforces the JEP 290 MaxRef and MaxDepth deserialization filters to prevent denial of service attacks.
As a temporary workaround, consider restricting the use of the Object Request Broker (ORB) until a patch is available.
Fix
DoS
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Ibm Aix
Ibm Sdk
Red Hat
Suse