CVE-2024-27267

T

he Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads.

References
Link Resource
https://www.ibm.com/support/pages/node/7165421 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:java_sdk:*:*:*:*:java_technology:*:*:*
cpe:2.3:a:ibm:java_sdk:*:*:*:*:java_technology:*:*:*

History

29 Sep 2025, 17:15

Type Values Removed Values Added
Summary (en) The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads. IBM X-Force ID: 284573. (en) The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads.
CWE CWE-300 CWE-362
References
  • {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/284573', 'tags': ['Vendor Advisory'], 'source': '[email protected]'}

11 Sep 2024, 13:48

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/284573 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/284573 - Vendor Advisory
References () https://www.ibm.com/support/pages/node/7165421 - () https://www.ibm.com/support/pages/node/7165421 - Vendor Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:ibm:java_sdk:*:*:*:*:java_technology:*:*:*
First Time Ibm java Sdk
Ibm

14 Aug 2024, 17:49

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-14 16:15

Updated : 2025-09-29 17:15


NVD link : CVE-2024-27267

Mitre link : CVE-2024-27267

CVE.ORG link : CVE-2024-27267


JSON object : View

Products Affected
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

NVD-CWE-noinfo