Impact
The vulnerability allows a causes the IBM WebSphere Application Server to consume excessive resources, leading to a denial of service. This flaw is classified as CWE-400 (Uncontrolled Resource Consumption). The primary impact is reduced availability for the affected service.
Affected Systems
IBM WebSphere Application Server prior to versions 8.5.5.31 and 9.0.5.29 are vulnerable until the relevant fix pack is applied.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the lack of EPSS data coupled with the vulnerability not being listed in the KEV catalog suggests a lower current exploitation probability. Nevertheless, as the issue is a remote denial of service, an attacker could trigger widespread resource exhaustion if the server is exposed to external traffic. The fix is recommended to mitigate the risk.
OpenCVE Enrichment