IBM Safer Payments
cpe:2.3:a:ibm:safer_payments:*:*:*:*:*:*:*
- >= 6.4.0.00, <= 6.4.2.07
- >= 6.5.0.00, <= 6.5.0.05
- >= 6.6.0.00, <= 6.6.0.03
A denial-of-service vulnerability has been identified in IBM Safer Payments versions 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03. This vulnerability allows remote attackers to cause a denial of service by exploiting improper resource allocation, which can lead to buffer overflow and uncontrolled memory allocation errors. These issues can occur when remote systems send arbitrarily large requests to the Message Command Interface (MCI).
Exploitation of this vulnerability can lead to a denial-of-service condition, causing the application to become unresponsive or unavailable.
Users are advised to update IBM Safer Payments to version 6.4.2.08, 6.5.0.06, 6.6.0.04, 6.7.0.00 or higher. For the Message Command Interface (MCI), it is recommended to use TLS with client certificate validation or to implement an allow-list of IP addresses that may connect, reducing the number of remote systems that can exploit the vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.