7.5
CVE-2024-39743
- EPSS 0.23%
- Veröffentlicht 08.07.2024 14:15:02
- Zuletzt bearbeitet 21.11.2024 09:28:20
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edition is vulnerable to denial of service caused by incorrect memory de-allocation. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 297172.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Mq Operator Version >= 2.0.0 < 2.0.24
Ibm ≫ Mq Operator Version >= 2.2.0 <= 2.2.2
Ibm ≫ Mq Operator Version >= 2.3.0 <= 2.3.3
Ibm ≫ Mq Operator Version >= 2.4.0 <= 2.4.8
Ibm ≫ Mq Operator Version >= 3.1.0 <= 3.1.3
Ibm ≫ Mq Operator Version >= 3.2.0 < 3.2.2
Ibm ≫ Mq Operator Version3.0.0
Ibm ≫ Mq Operator Version3.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.451 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| psirt@us.ibm.com | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-405 Asymmetric Resource Consumption (Amplification)
The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."