CVE-2023-38264: IBM SDK, Java Technology Edition denial of service
The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578.
Other sources
The IBM SDK, Java Technology Edition's Object Request Broker (ORB) is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters.
IBM Security Update May 2024: https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBMSecurityUpdateMay2024 https://www.ibm.com/support/pages/apar/IX90196 https://www.ibm.com/support/pages/node/7150727
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38264?
CVE-2023-38264 has been classified as a denial of service vulnerability.
How do I fix CVE-2023-38264?
To remediate CVE-2023-38264, update the IBM SDK, Java Technology Edition to version 8.0.8.25 or later.
Which versions are affected by CVE-2023-38264?
CVE-2023-38264 affects IBM SDK versions 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21.
What products are impacted by CVE-2023-38264?
CVE-2023-38264 impacts the IBM Storage Protect Backup-Archive Client versions 8.1.0.0 through 8.1.23.0.
What conditions lead to the vulnerability CVE-2023-38264?
CVE-2023-38264 occurs due to improper enforcement of JEP 290 MaxRef and MaxDepth deserialization filters.