CVE-2024-22871: High severity ibm cognos analytics vulnerability

Published Feb 29, 2024
·
Updated

An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn5920 function.

Other sources

Any program on the JVM may read serialized objects via java.io.ObjectInputStream.readObject(). Reading serialized objects from an untrusted source is inherently unsafe (this affects any program running on any version of the JVM) and is a prerequisite for this vulnerability.

Clojure classes that represent infinite seqs (Cycle, infinite Repeat, and Iterate) do not define hashCode() and use the parent ASeq.hashCode(), which walks the seq to compute the hash, yielding an infinite loop. Classes like java.util.HashMap call hashCode() on keys during deserialization of a serialized map.

The exploit requires:

1. Crafting a serialized HashMap object with an infinite seq object as a key. 2. Sending that to a program that reads serialized objects via ObjectInputStream.readObject().

This will cause the program to enter an infinite loop on the reading thread and thus a denial of service (DoS).

The affected Clojure classes (Cycle, Repeat, Iterate) exist in Clojure 1.7.0-1.11.1, 1.12.0-alpha1-1.12.0-alpha8.

GitHub

Clojure is vulnerable to a denial of service, caused by a flaw in the clojure.core$partial$fn5920 function. A remote attacker could exploit this vulnerability to cause a denial of service.

IBM

Affected Software

16 affected componentsFixes available
maven/org.clojure:clojure>=1.12.0-alpha1<1.12.0-alpha9
1.12.0-alpha9
maven/org.clojure:clojure>=1.7.0<1.11.2
1.11.2
IBM Cognos Analytics<=12.0.0-12.0.3
IBM Cognos Analytics<=11.2.0-11.2.4 FP4
Clojure Clojure>=1.2.0<1.11.2
Clojure Clojure=1.12.0-alpha1
Clojure Clojure=1.12.0-alpha2
Clojure Clojure=1.12.0-alpha3
Clojure Clojure=1.12.0-alpha4
Clojure Clojure=1.12.0-alpha5
Clojure Clojure=1.12.0-alpha6
Clojure Clojure=1.12.0-alpha7
Clojure Clojure=1.12.0-alpha8
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Fedoraproject Fedora=40

Event History

Feb 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
Affected Software
Advisory Published
via GitHub·03:33 AM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-22871?

CVE-2024-22871 has a severity rating that indicates it can cause a denial of service (DoS) in affected applications.

2

How do I fix CVE-2024-22871?

To fix CVE-2024-22871, you should upgrade to Clojure version 1.12.0-alpha9 or 1.11.2, or apply the appropriate patches for IBM Cognos Analytics.

3

Which versions of Clojure are affected by CVE-2024-22871?

CVE-2024-22871 affects Clojure versions 1.20 to 1.12.0-alpha5.

4

What functionalities are impacted by CVE-2024-22871?

CVE-2024-22871 impacts the functionality of the clojure.core$partial$fn__5920 function, potentially leading to DoS.

5

Is CVE-2024-22871 a remote vulnerability?

CVE-2024-22871 can be exploited locally or remotely, allowing attackers to affect any JVM-based application that uses the vulnerable versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203