IBM Websphere Edge Server Denial Of Service Vulnerability
BID:10651
Info
IBM Websphere Edge Server Denial Of Service Vulnerability
| Bugtraq ID: | 10651 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2004 12:00AM |
| Updated: | Jul 02 2004 12:00AM |
| Credit: | Leandro Meiners <[email protected]> disclosed this issue. |
| Vulnerable: |
IBM Websphere Edge server Caching proxy 5.0 2 IBM WebSphere Caching Proxy Server 5.0 2 |
| Not Vulnerable: |
IBM Websphere Edge server Caching proxy 5.0 IBM WebSphere Caching Proxy Server 5.0 |
Discussion
IBM Websphere Edge Server Denial Of Service Vulnerability
A denial of service vulnerability is reported in the Caching Proxy component bundled with the IBM Websphere Edge Server.
It is reported that if the proxy is configured with the JunctionRewrite directive in conjunction with the UseCookie option, an attacker may be able to crash the application.
A remote attacker reportedly is able to cause a denial of service condition with one request.
IBM has released a patch dealing with this issue. This patch is available only to customers with support levels 2 or 3.
A denial of service vulnerability is reported in the Caching Proxy component bundled with the IBM Websphere Edge Server.
It is reported that if the proxy is configured with the JunctionRewrite directive in conjunction with the UseCookie option, an attacker may be able to crash the application.
A remote attacker reportedly is able to cause a denial of service condition with one request.
IBM has released a patch dealing with this issue. This patch is available only to customers with support levels 2 or 3.
Exploit / POC
IBM Websphere Edge Server Denial Of Service Vulnerability
No exploit is required, but an example was provided:
echo ?GET? | nc www.example.com <proxy_port>
No exploit is required, but an example was provided:
echo ?GET? | nc www.example.com <proxy_port>
Solution / Fix
IBM Websphere Edge Server Denial Of Service Vulnerability
Solution:
IBM has released a patch dealing with this issue. This patch is only available to customers with support levels 2 or 3. It is also reported that Websphere version 5.0.3 will include the fix when it is released.
Solution:
IBM has released a patch dealing with this issue. This patch is only available to customers with support levels 2 or 3. It is also reported that Websphere version 5.0.3 will include the fix when it is released.
References
IBM Websphere Edge Server Denial Of Service Vulnerability
References:
References: