IBM Terracotta Ehcache Hash Flooding Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in the Ehcache 3.x component of IBM Terracotta, specifically in versions 10.15.0 prior to 10.15.0 Fix 23 and 11.1.0 prior to 11.1.0 Fix 5. This vulnerability can degrade cache-write performance in applications that use cache keys from external parties without proper filtering or salting.
Impact
Exploitation of this vulnerability can lead to degraded cache-write performance, causing potential slowdowns in application response times.
Remediation
Users are advised to upgrade to IBM Terracotta 11.1.0 Fix 6 or later, or IBM Terracotta 10.15.0 Fix 24 or later. These updates can be downloaded via the IBM webMethods Update Manager.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
