3.5

CVE-2025-2134

IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmJazz Reporting Service Version7.0.3 Update-
IbmJazz Reporting Service Version7.0.3 Updateifix001
IbmJazz Reporting Service Version7.0.3 Updateifix002
IbmJazz Reporting Service Version7.0.3 Updateifix003
IbmJazz Reporting Service Version7.0.3 Updateifix004
IbmJazz Reporting Service Version7.0.3 Updateifix005
IbmJazz Reporting Service Version7.0.3 Updateifix006
IbmJazz Reporting Service Version7.0.3 Updateifix007
IbmJazz Reporting Service Version7.0.3 Updateifix008
IbmJazz Reporting Service Version7.0.3 Updateifix009
IbmJazz Reporting Service Version7.0.3 Updateifix010
IbmJazz Reporting Service Version7.0.3 Updateifix011
IbmJazz Reporting Service Version7.0.3 Updateifix012
IbmJazz Reporting Service Version7.0.3 Updateifix013
IbmJazz Reporting Service Version7.0.3 Updateifix014
IbmJazz Reporting Service Version7.0.3 Updateifix015
IbmJazz Reporting Service Version7.0.3 Updateifix016
IbmJazz Reporting Service Version7.0.3 Updateifix017
IbmJazz Reporting Service Version7.0.3 Updateifix018
IbmJazz Reporting Service Version7.0.3 Updateifix019
IbmJazz Reporting Service Version7.0.3 Updateifix020
IbmJazz Reporting Service Version7.1 Update-
IbmJazz Reporting Service Version7.1 Updateifix001
IbmJazz Reporting Service Version7.1 Updateifix002
IbmJazz Reporting Service Version7.1 Updateifix003
IbmJazz Reporting Service Version7.1 Updateifix004-sr1-base
IbmJazz Reporting Service Version7.1 Updateifix005
IbmJazz Reporting Service Version7.1 Updateifix006
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.021
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 3.5 2.1 1.4
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-410 Insufficient Resource Pool

The product's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.