CVE-2020-4325
Last modified
CVE-2020-4325 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The IBM Process Federation Server 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, and 19.0.0.3 Global Teams REST API does not properly shutdown the thread pools that it creates to retrieve Global Teams information from the federated systems. As a consequence, the Java Virtual Machine can't recover the memory used by those thread pools, which leads to an OutOfMemory exception when the Process Federation Server Global Teams REST API is used extensively. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
The IBM Process Federation Server 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, and 19.0.0.3 Global Teams REST API does not properly shutdown the thread pools that it creates to retrieve Global Teams information from the federated systems. As a consequence, the Java Virtual Machine can't recover the memory used by those thread pools, which leads to an OutOfMemory exception when the Process Federation Server Global Teams REST API is used extensively. IBM X-Force ID: 177596.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Cloud Pak For Automation | 19.0.3 |
| Ibm | Process Federation Server | >= 18.0.0.1, <= 19.0.0.3 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/177596VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6125403Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/177596VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6125403Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-4325?
How severe is CVE-2020-4325?
How do I fix CVE-2020-4325?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-4318IBM Intelligent Operations Center for Emergency Management, …5.4
- CVE-2020-4319IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.…4.3
- CVE-2020-4320IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 …6.5
- CVE-2020-4322IBM Security Secret Server 10.7 could allow a remote attacke…4.3
- CVE-2020-4323IBM Security Secret Server 10.7 is vulnerable to cross-site …6.1
- CVE-2020-4324IBM Security Secret Server proir to 10.9 could allow a remot…4.3
- CVE-2020-4327IBM Security Secret Server 10.7 could allow a remote attacke…5.3
- CVE-2020-4328IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL…6.3
- CVE-2020-4329IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Libe…4.3
- CVE-2020-4336IBM WebSphere eXtreme Scale 8.6.1 stores sensitive informati…5.3
- CVE-2020-4337IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow a…6.5
- CVE-2020-4338IBM MQ 9.1.4 could allow a local attacker to obtain sensitiv…5.5
Are you affected by CVE-2020-4325?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
