PT-2024-5598 · Ibm+11 · Ibm Sdk+14

Yakov Shafranovich

·

Published

2024-07-16

·

Updated

2026-05-08

·

CVE-2024-21144

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 8u411, 8u411-perf, 11.0.23 Oracle GraalVM Enterprise Edition versions 20.3.14, 21.3.10 IBM SDK, Java Technology Edition versions 7.1.0.0 through 7.1.5.18 IBM SDK, Java Technology Edition versions 8.0.0.0 through 8.0.8.26
Description The issue is related to insufficient input validation in the Concurrency component, allowing an unauthenticated attacker with network access via multiple protocols to compromise the system. Successful attacks can result in a partial denial of service. This issue applies to Java deployments that load and run untrusted code and rely on the Java sandbox for security, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets. The vulnerability does not apply to Java deployments that load and run only trusted code, typically in servers.
Recommendations For Oracle Java SE versions 8u411, 8u411-perf, 11.0.23, update to a version that includes the fix for this issue. For Oracle GraalVM Enterprise Edition versions 20.3.14, 21.3.10, update to a version that includes the fix for this issue. For IBM SDK, Java Technology Edition versions 7.1.0.0 through 7.1.5.18, update to a version outside of this range. For IBM SDK, Java Technology Edition versions 8.0.0.0 through 8.0.8.26, update to a version outside of this range. As a temporary workaround, consider restricting access to the Concurrency component until a patch is available.

Exploit

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4563
ALSA-2024:4567
ALT-PU-2024-17629
ALT-PU-2024-17630
ALT-PU-2024-17633
ALT-PU-2024-17637
ALT-PU-2024-17641
ALT-PU-2024-17642
ALT-PU-2025-1037
ALT-PU-2025-6317
BDU:2024-06285
BIT-JAVA-2024-21144
BIT-JAVA-MIN-2024-21144
BIT-JRE-2024-21144
CESA-2024_4563
CESA-2024_4567
CVE-2024-21144
DSA-5736-1
INFSA-2024_4563
INFSA-2024_4567
MGASA-2024-0319
OESA-2024-1906
OESA-2024-1907
OESA-2024-1908
OESA-2024-1909
OESA-2024-1957
OESA-2024-1958
OESA-2024-2485
OESA-2024-2486
OESA-2024-2487
OESA-2024-2488
OESA-2024-2489
OPENSUSE-SU-2024:14206-1
OPENSUSE-SU-2024:14233-1
OPENSUSE-SU-2024_2786-1
OPENSUSE-SU-2024_3140-1
OPENSUSE-SU-2024_3162-1
OPENSUSE-SU-2025:0066-1
RHSA-2024:4560
RHSA-2024:4563
RHSA-2024:4564
RHSA-2024:4567
RHSA-2024_4563
RHSA-2024_4567
SUSE-SU-2024:2590-1
SUSE-SU-2024:2629-1
SUSE-SU-2024:2766-1
SUSE-SU-2024:2786-1
SUSE-SU-2024:3140-1
SUSE-SU-2024:3162-1
SUSE-SU-2024:3183-1
USN-6929-1
USN-6930-1
USN-7096-1
USN-7096-2
USN-7097-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Graalvm Enterprise Edition
Ibm Aix
Ibm Sdk
Java Platform
Java Se
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu