CVE-2023-38264

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published May 14, 2024
CWE ID 502

Summary

CVE-2023-38264 is a vulnerability that affects the IBM SDK, Java Technology Edition's Object Request Broker (ORB) versions 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21, allowing for a denial of service attack due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. The vulnerability has a base severity rating of MEDIUM and an exploitability score of 2.2 out of 10. It poses a potential danger to organizations as it can lead to a network-based attack with high availability impact, potentially causing disruption or unavailability of services. There is no user interaction or privileges required for exploitation, making it easier for attackers to target vulnerable systems over the network. It is recommended to apply patches or updates provided by IBM to remediate this vulnerability and mitigate any potential risks it poses to the organization's systems and infrastructure. Note: The given text provides information about the vulnerability but lacks specific details about how to remediate it or any potential danger it poses to an organization beyond what is mentioned in the analysis_description field ('None').

Share

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-38264 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options