VMware Identity Manager vulnerability CVE-2024-27316
search cancel

VMware Identity Manager vulnerability CVE-2024-27316

book

Article ID: 378236

calendar_today

Updated On:

Products

VMware Aria Suite

Issue/Introduction

Does vIDM 3.3.7 is affected by this following vulnerability CVE-2024-27316

Environment

VMware Identity Manager 3.3.7

Resolution

VMware Identity Manager 3.3.7 is not impacted by CVE-2024-27316 because it uses HTTP/1.1 rather than HTTP/2.

Additional Information

Vulnerability Details : Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames (CVE-2024-27316)
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.