Impact
IBM WebSphere eXtreme Scale versions 8.6.1.0 through 8.6.1.6 contain an uncontrolled resource consumption flaw in the XDF decoder. The decoder tolerates deeply nested Protocol Buffers messages with attacker‑controlled length prefixes and fails to perform adequate bounds checking. An attacker can supply a malicious payload that triggers a StackOverflowError or an OutOfMemoryError, causing the WebSphere Application Server JVM to crash and resulting in a denial of service. The vulnerability is an example of CWE‑400: Uncontrolled Resource Consumption.
Affected Systems
The affected product is IBM WebSphere eXtreme Scale, specifically the 8.6.1.0 to 8.6.1.6 release range. An attacker must be on the same network or otherwise able to interact directly with the XDF decoding endpoint. The impact is limited to the affected instance of WebSphere eXtreme Scale; other IBM or non‑IBM products are not mentioned as vulnerable.
Risk and Exploitability
The CVSS score for this flaw is 6.5, indicating moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that publicly known exploitation is not documented. However, the flaw can be exploited by an adjacent attacker who can send malicious XDF messages, which is likely for systems with exposed internal interfaces. Given the need for network proximity and the potential for a local denial of service, the risk is moderate to high for environments that run the vulnerable product without adequate segmentation.
OpenCVE Enrichment