PT-2002-2746 · Ibm · Lotus Domino Server

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-2025

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Lotus Domino server versions 5.0.9a and earlier
Description The issue allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests. This can be achieved by sending requests for an MS-DOS device name, or an MS-DOS device name with a large number of characters appended to the device name.
Recommendations For versions 5.0.9a and earlier, consider restricting access to the HTTP request handling mechanism to minimize the risk of exploitation. As a temporary workaround, limit the number of concurrent HTTP requests to prevent thread exhaustion.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-2025

Produtos afetados

Lotus Domino Server