QID 378993
Date Published: 2023-11-09
QID 378993: IBM Integration Bus Toolkit denial of service Vulnerability (7056518)
IBM Integration Bus Toolkit using Maven projects feature are vulnerable to a denial of service due to Okio GzipSource.
Affected Products and Versions:
IBM Integration Bus 10.1 - 10.1.0.1
QID Detection Logic (Authenticated):
Operating System: Windows and Linux: The QID checks if a vulnerable version of IBM Integration Bus is installed on the system.
By sending a specially crafted gzip buffer, a remote attacker could exploit this vulnerability to cause a denial of service.
Solution
Users are advised to follow the patching procedure provided by IBM. Further information can be obtained from IBM Security Bulletin (7056518)
Vendor References
- 7056518 -
www.ibm.com/support/pages/node/7056518
CVEs related to QID 378993
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7056518 |
|