CVE-2020-4325
Published: Apr 2, 2020
Modified: Sep 16, 2024
CVSS v3.0
6.5
Description
The IBM Process Federation Server 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, and 19.0.0.3 Global Teams REST API does not properly shutdown the thread pools that it creates to retrieve Global Teams information from the federated systems. As a consequence, the Java Virtual Machine can't recover the memory used by those thread pools, which leads to an OutOfMemory exception when the Process Federation Server Global Teams REST API is used extensively. IBM X-Force ID: 177596.
| Vendor | Product | Versions |
|---|---|---|
IBM | Process Federation Server | affected 18.0.0.1affected 18.0.0.2affected 19.0.0.1affected 19.0.0.2affected 19.0.0.3 |
IBM | Automation Workstream Services in Cloud Pak for Automation | affected 19.0.0.3 |
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/C:N/S:U/A:H/PR:L/I:N/AV:N/AC:L/UI:N/RC:C/E:U/RL:O
Confidentiality
Scope
Availability
Privileges Required
Integrity
Attack Vector
Attack Complexity
User Interaction
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now