IBM Tivoli Policy Director WebSeal Denial Of Service Vulnerability
BID:3685
Info
IBM Tivoli Policy Director WebSeal Denial Of Service Vulnerability
| Bugtraq ID: | 3685 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-1191 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | This vulnerability was submitted to BugTraq by Matthew Lane <[email protected]> on December 11th, 2001. |
| Vulnerable: |
IBM Tivoli SecureWay Policy Director 3.8 |
| Not Vulnerable: | |
Discussion
IBM Tivoli Policy Director WebSeal Denial Of Service Vulnerability
WebSeal is the proxy component of the IBM Tivoli Policy Director. It is able to provide authentication and control web access by filtering HTTP requests.
WebSeal is prone to denial of service attacks. If a '%2e' is appended to the end of a web request, this will cause WebSeal to stop operating when it tries to process the URL.
It has been reported that this is related to the use of SSL junctions between the WebSeal component and web servers. The WebSeal component may fail when certain URLs are passed across this connection.
WebSeal is the proxy component of the IBM Tivoli Policy Director. It is able to provide authentication and control web access by filtering HTTP requests.
WebSeal is prone to denial of service attacks. If a '%2e' is appended to the end of a web request, this will cause WebSeal to stop operating when it tries to process the URL.
It has been reported that this is related to the use of SSL junctions between the WebSeal component and web servers. The WebSeal component may fail when certain URLs are passed across this connection.
Exploit / POC
IBM Tivoli Policy Director WebSeal Denial Of Service Vulnerability
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.
Solution / Fix
IBM Tivoli Policy Director WebSeal Denial Of Service Vulnerability
Solution:
IBM has announced that this issue is resolved in IBM Tivoli Policy Director WebSEAL 3.8 Fixpack 1, available to registered customers at the following location:
https://www.tivoli.com/secure/support/patches/Tivoli_SecureWay_Policy_Director_WebSEAL_.html#3.8-PWS-0001
Solution:
IBM has announced that this issue is resolved in IBM Tivoli Policy Director WebSEAL 3.8 Fixpack 1, available to registered customers at the following location:
https://www.tivoli.com/secure/support/patches/Tivoli_SecureWay_Policy_Director_WebSEAL_.html#3.8-PWS-0001
References
IBM Tivoli Policy Director WebSeal Denial Of Service Vulnerability
References:
References: