Vulnerability CVE-2023-38264


Published: 2024-05-14

Description:
The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578.

Type:

CWE-502

(Deserialization of Untrusted Data)

 References:
https://exchange.xforce.ibmcloud.com/vulnerabilities/260578
https://www.ibm.com/support/pages/node/7150727

Copyright 2026, cxsecurity.com

 

Back to Top