Impact
IBM WebSphere Application Server, including the Liberty profile, as well as IBM PowerVM Novalink, are vulnerable to a denial‑of‑service condition when a remote attacker sends a specially crafted request that causes the server to consume excessive memory. This uncontrolled resource consumption (CWE‑400) can exhaust available memory and render the appliance unresponsive, disrupting business operations. The vulnerability is identified with a CVSS score of 7.5, indicating a high‑severity risk.
Affected Systems
The vulnerability impacts IBM PowerVM Novalink appliances. All installations running versions earlier than pvm‑novalink‑2.2.1.1‑260708 or pvm‑novalink‑2.3.3‑260714 are affected. IBM recommends upgrading to either of those releases to remediate the issue.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, but the CVE description does not specify the attack complexity or specific vector. The EPSS score of less than 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that a remote attacker would need to send a crafted request over the network to trigger memory exhaustion on the Novalink appliance.
OpenCVE Enrichment