PT-2024-12693 · Ibm+3 · Ibm Sdk+4

Published

2024-05-10

·

Updated

2025-08-14

·

CVE-2023-38264

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM SDK, Java Technology Edition versions 7.1.0.0 through 7.1.5.21 IBM SDK, Java Technology Edition versions 8.0.0.0 through 8.0.8.21
Description The issue is related to a denial of service attack due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters in the Object Request Broker (ORB). This can occur under certain circumstances.
Recommendations For versions 7.1.0.0 through 7.1.5.21, update to a version that properly enforces the JEP 290 MaxRef and MaxDepth deserialization filters to prevent denial of service attacks. For versions 8.0.0.0 through 8.0.8.21, update to a version that properly enforces the JEP 290 MaxRef and MaxDepth deserialization filters to prevent denial of service attacks. As a temporary workaround, consider restricting the use of the Object Request Broker (ORB) until a patch is available.

Fix

DoS

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CESA-2024_3685
CVE-2023-38264
OPENSUSE-SU-2024_1859-1
RHSA-2024:3685
RHSA-2024:4160
RHSA-2024_3685
RHSA-2024_4160
SUSE-SU-2024:1845-1
SUSE-SU-2024:1859-1
SUSE-SU-2024_1845-1
SUSE-SU-2024_1859-1

Affected Products

Centos
Ibm Aix
Ibm Sdk
Red Hat
Suse