Download
Downloadable File
| File link | File size | File description |
|---|---|---|
Abstract
IBM WebSphere Application Server is affected by a denial of service due to jose4j (CVE-2024-29371 CVSS 7.5)
Download Description
This fix has been superseded by a fix for another APAR. For information on how to obtain the latest OpenID Connect runtime that includes this APAR, see the technote Obtaining WebSphere OpenID Connect (OIDC) latest version.
PH69757 resolves the following problem:
ERROR DESCRIPTION:
ERROR DESCRIPTION:
IBM WebSphere Application Server is affected by a denial of service due to jose4j (CVE-2024-29371 CVSS 7.5)
PROBLEM CONCLUSION:
Confidential for CVE-2024-29371 CVSS 7.5.
The fix for PH69757 is targeted for inclusion in fix pack 8.5.5.30 and 9.0.5.27. Refer to the Recommended Updates page for delivery information: http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
This fix has been superseded by a fix for another APAR. For information on how to obtain the latest OpenID Connect runtime that includes this APAR, see the technote Obtaining WebSphere OpenID Connect (OIDC) latest version.
Download Package
Problems Solved
IFPH69757
Change History
Off
Document Location
Worldwide
[{"Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"ARM Category":[{"code":"a8m50000000CdESAA0","label":"Security-\u003ESSO-\u003EOpenId Connect"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5.5;9.0.0;9.0.5"}]
Was this topic helpful?
Document Information
Modified date:
27 July 2026
UID
ibm17257605