IBM Safer Payments Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in IBM Safer Payments versions 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03. This vulnerability allows remote attackers to cause a denial of service by exploiting improper resource allocation, which can lead to buffer overflow and uncontrolled memory allocation errors. These issues can occur when remote systems send arbitrarily large requests to the Message Command Interface (MCI).

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, causing the application to become unresponsive or unavailable.

Remediation

Users are advised to update IBM Safer Payments to version 6.4.2.08, 6.5.0.06, 6.6.0.04, 6.7.0.00 or higher. For the Message Command Interface (MCI), it is recommended to use TLS with client certificate validation or to implement an allow-list of IP addresses that may connect, reducing the number of remote systems that can exploit the vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
7.0
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.