Asymmetric denial of service - ReDoS In java-21-ibm-semeru-certified-jdk
Description
A flaw was found in Eclipse Open9J and JITServer. A remote attacker, without needing to authenticate, can send a specially crafted 32-byte TCP message to JITServer. This action can cause JITServer to crash, leading to a Denial of Service (DoS) for affected systems.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel10.0 | 1:21.0.11.0.10-1.el10_0 | ||
rpm rhel10 | 1:21.0.11.0.10-2.el10_1 |
Aliases
1. 2. 3.