PT-2012-2391 · Ibm · Ibm Websphere Application Server

Publicado

2012-01-20

·

Atualizado

2012-01-27

·

CVE-2012-0193

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server (WAS) versions 6.0 through 6.0.2.43 IBM WebSphere Application Server (WAS) versions 6.1 before 6.1.0.43 IBM WebSphere Application Server (WAS) versions 7.0 before 7.0.0.23 IBM WebSphere Application Server (WAS) versions 8.0 before 8.0.0.3
Description The issue allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, due to the computation of hash values for form parameters without restricting the ability to trigger hash collisions predictably.
Recommendations For versions 6.0 through 6.0.2.43, update to a version after 6.0.2.43 to resolve the issue. For versions 6.1 before 6.1.0.43, update to version 6.1.0.43 or later to resolve the issue. For versions 7.0 before 7.0.0.23, update to version 7.0.0.23 or later to resolve the issue. For versions 8.0 before 8.0.0.3, update to version 8.0.0.3 or later to resolve the issue.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-0193

Produtos afetados

Ibm Websphere Application Server