Description
The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-42084 | The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578. |
References
History
Thu, 14 Aug 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm
Ibm java Software Development Kit |
|
| CPEs | cpe:2.3:a:ibm:java_software_development_kit:*:*:*:*:java_technology:*:*:* | |
| Vendors & Products |
Ibm
Ibm java Software Development Kit |
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-02T17:39:12.051Z
Reserved: 2023-07-14T00:46:14.889Z
Link: CVE-2023-38264
Updated: 2024-08-02T17:39:12.051Z
Status : Analyzed
Published: 2024-05-14T13:21:29.417
Modified: 2025-08-14T19:34:02.877
Link: CVE-2023-38264
OpenCVE Enrichment
No data.
EUVD