CVE-2024-25026: IBM WebSphere Application Server denial of service
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 281516.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25026?
CVE-2024-25026 is classified as a denial of service vulnerability that can significantly impact system availability.
How do I fix CVE-2024-25026?
To mitigate CVE-2024-25026, update IBM WebSphere Application Server to the latest patched version as provided by IBM.
Which versions of IBM WebSphere are affected by CVE-2024-25026?
CVE-2024-25026 affects IBM WebSphere Application Server versions 8.5, 9.0, and Liberty versions 17.0.0.3 through 24.0.0.4.
Can CVE-2024-25026 be exploited remotely?
Yes, CVE-2024-25026 can be exploited remotely by sending specially crafted requests to the server.
What impact does CVE-2024-25026 have on system performance?
CVE-2024-25026 can cause increased resource consumption, potentially leading to service denial.