IBM WebSphere DataPower XML Security Gateway XS40 Remote Denial Of Service Vulnerability
BID:33169
Info
IBM WebSphere DataPower XML Security Gateway XS40 Remote Denial Of Service Vulnerability
| Bugtraq ID: | 33169 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 08 2009 12:00AM |
| Updated: | Jan 08 2009 06:42PM |
| Credit: | [email protected] |
| Vulnerable: |
IBM WebSphere DataPower XML Security Gateway XS40 3.6.1 .5 |
| Not Vulnerable: |
IBM WebSphere DataPower XML Security Gateway XS40 3.6.1 .12 |
Discussion
IBM WebSphere DataPower XML Security Gateway XS40 Remote Denial Of Service Vulnerability
IBM WebSphere DataPower XML Security Gateway XS40 is prone to a remote denial-of-service vulnerability because it fails to handle user-supplied input.
Remote attackers can exploit this issue to cause the device to reboot, denying service to legitimate users.
WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 is affected; other versions may also be vulnerable.
IBM WebSphere DataPower XML Security Gateway XS40 is prone to a remote denial-of-service vulnerability because it fails to handle user-supplied input.
Remote attackers can exploit this issue to cause the device to reboot, denying service to legitimate users.
WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 is affected; other versions may also be vulnerable.
Exploit / POC
IBM WebSphere DataPower XML Security Gateway XS40 Remote Denial Of Service Vulnerability
Attackers can exploit this issue with readily available tools.
The following string is sufficient to trigger this issue:
?abc?
Attackers can exploit this issue with readily available tools.
The following string is sufficient to trigger this issue:
?abc?
Solution / Fix
IBM WebSphere DataPower XML Security Gateway XS40 Remote Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
IBM WebSphere DataPower XML Security Gateway XS40 Remote Denial Of Service Vulnerability
References:
References: