CVE-2024-27267

The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads.
References
Link Resource
https://www.ibm.com/support/pages/node/7165421 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:java_sdk:*:*:*:*:java_technology:*:*:*
cpe:2.3:a:ibm:java_sdk:*:*:*:*:java_technology:*:*:*

History

29 Sep 2025, 17:15

Type Values Removed Values Added
Summary (en) The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads. IBM X-Force ID: 284573. (en) The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads.
References
  • {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/284573', 'tags': ['Vendor Advisory'], 'source': 'psirt@us.ibm.com'}
CWE CWE-300 CWE-362

11 Sep 2024, 13:48

Type Values Removed Values Added
First Time Ibm java Sdk
Ibm
Summary
  • (es) El Object Request Broker (ORB) en IBM SDK, Java Technology Edition 7.1.0.0 a 7.1.5.18 y 8.0.0.0 a 8.0.8.26 es vulnerable a la denegación remota de servicio, provocada por una condición de ejecución en la gestión de subprocesos de escucha de ORB. ID de IBM X-Force: 284573.
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:ibm:java_sdk:*:*:*:*:java_technology:*:*:*
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/284573 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/284573 - Vendor Advisory
References () https://www.ibm.com/support/pages/node/7165421 - () https://www.ibm.com/support/pages/node/7165421 - Vendor Advisory

14 Aug 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-14 16:15

Updated : 2025-09-29 17:15


NVD link : CVE-2024-27267

Mitre link : CVE-2024-27267

CVE.ORG link : CVE-2024-27267


JSON object : View

Products Affected

ibm

  • java_sdk
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

NVD-CWE-noinfo