Bug 2279963 (CVE-2023-38264) - CVE-2023-38264 IBM JDK: Object Request Broker (ORB) denial of service
Summary: CVE-2023-38264 IBM JDK: Object Request Broker (ORB) denial of service
Keywords:
Status: NEW
Alias: CVE-2023-38264
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2274351
TreeView+ depends on / blocked
 
Reported: 2024-05-10 08:04 UTC by Mauro Matteo Cascella
Modified: 2024-06-27 09:47 UTC (History)
0 users

Fixed In Version: java-1.8.0-ibm 8.0.8.25
Doc Type: ---
Doc Text:
The IBM SDK, Java Technology Edition's Object Request Broker (ORB) is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2024:3685 0 None None None 2024-06-06 13:13:00 UTC
Red Hat Product Errata RHSA-2024:4160 0 None None None 2024-06-27 09:47:11 UTC

Description Mauro Matteo Cascella 2024-05-10 08:04:53 UTC
The IBM SDK, Java Technology Edition's Object Request Broker (ORB) is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters.

IBM Security Update May 2024:
https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBM_Security_Update_May_2024
https://www.ibm.com/support/pages/apar/IX90196
https://www.ibm.com/support/pages/node/7150727

Comment 2 errata-xmlrpc 2024-06-06 13:12:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:3685 https://access.redhat.com/errata/RHSA-2024:3685

Comment 3 errata-xmlrpc 2024-06-27 09:47:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2024:4160 https://access.redhat.com/errata/RHSA-2024:4160


Note You need to log in before you can comment on or make changes to this bug.