s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2023-24971

📛 CVE Title

IBM B2B Advanced Communication denial of service

Description

IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to the deserializing of untrusted serialized Java objects. IBM X-Force ID: 246976.

Overview

State
PUBLISHED
Assigner (CNA)
ibm
CVSS severity
HIGH
CVSS score
CVSS 7.5 / 10 7.5 7.5 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Effective score
7.5 / 10 HIGH source: CNA overview
CWE(s)
CWE-502
Reserved
2023-02-01
Published
2023-07-31 03:16 UTC
Last updated
2024-10-18 22:22 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/24xxx/CVE-2023-24971.json
Linked Threat
CVE-2023-24971 — IBM B2B Advanced Communication denial of service

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2023-07-31 02:15:09 UTC
NVD last modified
2026-06-17 05:40:23 UTC
NVD CVSS v3.1
CVSS 7.5 / 10 7.5 7.5 / 10 HIGH source: psirt@us.ibm.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability subscore
3.9 / 10
Impact subscore
3.6 / 10
EPSS score
0.0070 (probability of exploitation in next 30 days)
EPSS percentile
49.54% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26

NVD / KEV / EPSS data refreshed 2026-07-27 13:54 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2023-28958
Assigner
ibm
Published
Jul 31, 2023, 1:16:37 AM
Updated
Oct 18, 2024, 8:22:44 PM
EUVD base score (CVSS 3.1)
7.5 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EUVD-reported EPSS
0.1100
Vendors
IBM
Products
Multi-Enterprise Integration Gateway (1.0.0.1)
B2B Advanced Communications (1.0.0.0)
Aliases
GHSA-mqv8-9v3c-wwh2

ENISA description: IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to the deserializing of untrusted serialized Java objects. IBM X-Force ID: 246976.

EUVD references (2)

Affected products (2)

VendorProductVersionsPlatforms
IBM B2B Advanced Communications 1.0.0.0 (affected)
IBM Multi-Enterprise Integration Gateway 1.0.0.1 (affected)

Affected products — CPE 2.3 (2) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:ibm:b2b_advanced_communications:*:*:*:*:*:*:*:*
  • cpe:2.3:a:ibm:multi-enterprise_integration_gateway:1.0.0.1:*:*:*:*:*:*:*

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

MITRE references (2) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

NVD-tagged references (4)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
ipv4 1.0.0.1 2026-05-22 02:37 UTC)">not flagged 2026-05-18 21:20 UTC
ipv4 1.0.0.0 no local data 2026-05-18 21:20 UTC

Flagged vendors

    Remediations (20)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:nvd.nist.gov

      Vulnerabilities All vulnerabilities in the NVD have been assigned a CVE identifier and thus, abide by the definition below. CVE defines a vulnerability as: "A weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, or availability. Mitigation of the vulnerabilities in this ...

      2026-06-07 09:33 UTC
    • web:translate.google.com

      Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.

      2026-06-07 09:33 UTC
    • web:blog.qualys.com

      As the year winds down, Microsoft Patch Tuesday in December arrives with essential fixes and enhancements to close vulnerabilities and boost performance.

      2026-06-07 09:33 UTC
    • web:access.redhat.com

      Learn about our open source products, services, and company. You are here

      2026-06-07 09:33 UTC
    • web:www.rapid7.com

      Microsoft has published 172 new vulnerabilities, including six zero-day vulnerabilities. Windows 10 moves past the end of support, sort of. Critical RCE in Windows Server Update Service.

      2026-06-07 09:33 UTC
    • web:www.oracle.com

      Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

      2026-06-07 09:33 UTC
    • web:attack.mitre.org

      This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...

      2026-06-07 09:33 UTC
    • web:www.zdnet.com

      ZDNET Microsoft's Patch Tuesday rollout for February is a big one, not simply in size but in scope. Rolled out on February 11, the latest updates not only add a few new features but squash several ...

      2026-05-22 05:59 UTC
    • web:krebsonsecurity.com

      October's Patch Tuesday also marks the final month that Microsoft will ship security updates for Windows 10 systems.

      2026-05-22 05:59 UTC
    • web:www.bleepingcomputer.com

      Microsoft has released Windows 11 KB5079473 and KB5078883 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.

      2026-05-22 05:59 UTC
    • web:www.bleepingcomputer.com

      Microsoft says customers in restricted network environments may encounter Windows Update failures after installing the January 2026 optional non-security preview updates.

      2026-05-22 03:55 UTC
    • web:cyberpress.org

      The third vulnerability, CVE -2026-44791 (GHSA-wrwr-h859-xh2r), is particularly alarming because it represents a patch bypass. It circumvents the previously issued fix for GHSA-hqr4-h3xv-9m3r in the XML node, reintroducing prototype pollution through a different code path. When chained with additional nodes, this too can escalate to RCE on the host.

      2026-05-22 03:55 UTC
    • web:www.computerworld.com

      Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...

      2026-05-22 03:55 UTC
    • web:www.cve.org

      At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

      2026-05-22 03:55 UTC
    • web:www.neowin.net

      Windows 11's March 2026 Patch Tuesday update is here under KB5079473 with File Explorer improvements and more.

      2026-05-22 03:55 UTC
    • web:www.notebookcheck.net

      Microsoft's March 2026 Patch Tuesday fixes 79 flaws, including two publicly disclosed zero-days. Windows 11 gets KB5079473 and KB5078883, while Windows 10 receives KB5078885.

      2026-05-22 03:55 UTC
    • web:krebsonsecurity.com

      Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known "zero-day" or actively exploited vulnerabilities ...

      2026-05-22 03:55 UTC
    • web:cybersecuritynews.com

      Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2.

      2026-05-22 03:55 UTC
    • web:www.windowscentral.com

      Another out of band update has been issued to Windows 11 users to address a major bug that caused Outlook to become inoperable after January's disastrous Patch Tuesday updates.

      2026-05-22 03:55 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-22 03:55 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2023-24971.json.

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:11:43.544Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://www.ibm.com/support/pages/node/7014933"
              },
              {
                "tags": [
                  "vdb-entry",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/246976"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-24971",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-18T20:22:22.867917Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-18T20:22:44.091Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "B2B Advanced Communications",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0.0"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Multi-Enterprise Integration Gateway",
              "vendor": "IBM",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.0.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n<span style=\"background-color: rgb(204, 217, 226);\">IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to the deserializing of untrusted serialized Java objects. IBM X-Force ID: 246976.</span>\n\n"
                }
              ],
              "value": "\nIBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to the deserializing of untrusted serialized Java objects. IBM X-Force ID: 246976.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "CWE-502 Deserialization of Untrusted Data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-07-31T01:16:37.346Z",
            "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
            "shortName": "ibm"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.ibm.com/support/pages/node/7014933"
            },
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/246976"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "IBM B2B Advanced Communication denial of service",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "assignerShortName": "ibm",
        "cveId": "CVE-2023-24971",
        "datePublished": "2023-07-31T01:16:37.346Z",
        "dateReserved": "2023-02-01T02:59:27.687Z",
        "dateUpdated": "2024-10-18T20:22:44.091Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }