IBM Terracotta Ehcache Hash Flooding Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Ehcache 3.x component of IBM Terracotta, specifically in versions 10.15.0 prior to 10.15.0 Fix 23 and 11.1.0 prior to 11.1.0 Fix 5. This vulnerability can degrade cache-write performance in applications that use cache keys from external parties without proper filtering or salting.

Impact

Exploitation of this vulnerability can lead to degraded cache-write performance, causing potential slowdowns in application response times.

Remediation

Users are advised to upgrade to IBM Terracotta 11.1.0 Fix 6 or later, or IBM Terracotta 10.15.0 Fix 24 or later. These updates can be downloaded via the IBM webMethods Update Manager.

Added: Oct 15, 2025, 4:33 PM
Updated: Oct 15, 2025, 4:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.