CVE Published: 10/05/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: ibm |
Vendor: IBM |
Product: SDK, Java Technology Edition Status : PUBLISHED
CVE-2023-38264 Description
The IBM SDK, Java Technology Edition\'s Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578.
Metrics
CVSS Version: 3.1 |
Base Score: 5.9 MEDIUM Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H