Cyber Posture

CVE-2024-41743

High

Published: 19 January 2025

Published
19 January 2025
Modified
16 July 2025
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0007 21.7th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocation of resources.

Security Summary

IBM TXSeries for Multiplatforms 10.1 is affected by CVE-2024-41743, a vulnerability that could allow a remote attacker to cause a denial of service through the use of persistent connections. This issue stems from improper allocation of resources, mapped to CWE-770 (Allocation of Resources Without Limits or Throttling). The vulnerability received a CVSS v3.1 base score of 7.5, reflecting its high severity primarily due to the availability impact.

A remote attacker with no privileges required can exploit this vulnerability over the network with low complexity and no user interaction. By leveraging persistent connections, the attacker can trigger excessive resource consumption, leading to a denial of service condition that disrupts service availability without impacting confidentiality or integrity.

The IBM security advisory provides details on mitigation and available patches; refer to https://www.ibm.com/support/pages/node/7172103 for specific remediation steps.

Details

CWE(s)
CWE-770

Affected Products

ibm
txseries for multiplatforms
10.1

References