IBM WebSphere Application Server Hash Collision Denial Of Service Vulnerability
BID:51441
Info
IBM WebSphere Application Server Hash Collision Denial Of Service Vulnerability
| Bugtraq ID: | 51441 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2012-0193 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2012 12:00AM |
| Updated: | Jul 04 2013 12:21PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
IBM Websphere Application Server 8.0 2 IBM Websphere Application Server 7.0 3 IBM Websphere Application Server 7.0 21 IBM Websphere Application Server 7.0 .9 IBM Websphere Application Server 7.0 .8 IBM Websphere Application Server 7.0 .2 IBM Websphere Application Server 7.0 .13 IBM Websphere Application Server 7.0 .12 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 6.1 41 IBM Websphere Application Server 6.1 .9 IBM Websphere Application Server 6.1 .8 IBM Websphere Application Server 6.1 .7 IBM Websphere Application Server 6.1 .6 IBM Websphere Application Server 6.1 .5 IBM Websphere Application Server 6.1 .4 IBM Websphere Application Server 6.1 .33 IBM Websphere Application Server 6.1 .32 IBM Websphere Application Server 6.1 .3 IBM Websphere Application Server 6.1 .25 IBM Websphere Application Server 6.1 .23 IBM Websphere Application Server 6.1 .22 IBM Websphere Application Server 6.1 .21 IBM Websphere Application Server 6.1 .20 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .19 IBM Websphere Application Server 6.1 .18 IBM Websphere Application Server 6.1 .17 IBM Websphere Application Server 6.1 .15 IBM Websphere Application Server 6.1 .14 IBM Websphere Application Server 6.1 .13 IBM Websphere Application Server 6.1 .12 IBM Websphere Application Server 6.1 .11 IBM Websphere Application Server 6.1 .10 IBM Websphere Application Server 6.1 .1 IBM Websphere Application Server 6.1 IBM Websphere Application Server 6.0.2 .9 IBM Websphere Application Server 6.0.2 .7 IBM Websphere Application Server 6.0.2 .5 IBM Websphere Application Server 6.0.2 .39 IBM Websphere Application Server 6.0.2 .35 IBM Websphere Application Server 6.0.2 .33 IBM Websphere Application Server 6.0.2 .31 IBM Websphere Application Server 6.0.2 .3 IBM Websphere Application Server 6.0.2 .29 IBM Websphere Application Server 6.0.2 .27 IBM Websphere Application Server 6.0.2 .25 IBM Websphere Application Server 6.0.2 .24 IBM Websphere Application Server 6.0.2 .23 IBM Websphere Application Server 6.0.2 .22 IBM Websphere Application Server 6.0.2 .21 IBM Websphere Application Server 6.0.2 .17 IBM Websphere Application Server 6.0.2 .15 IBM Websphere Application Server 6.0.2 .13 IBM Websphere Application Server 6.0.2 .11 IBM Websphere Application Server 6.0.2 .1 IBM Websphere Application Server 6.0.2 IBM Websphere Application Server 6.0.1 IBM Websphere Application Server 6.0 .7 IBM Websphere Application Server 6.0 IBM Websphere Application Server 8.0.0.1 IBM Websphere Application Server 8.0.0.0 IBM Websphere Application Server 8.0 IBM Websphere Application Server 7.0.0.7 IBM Websphere Application Server 7.0.0.6 IBM Websphere Application Server 7.0.0.5 IBM Websphere Application Server 7.0.0.4 IBM Websphere Application Server 7.0.0.19 IBM Websphere Application Server 7.0.0.17 IBM Websphere Application Server 7.0.0.15 IBM Websphere Application Server 7.0.0.15 IBM Websphere Application Server 7.0.0.14 IBM Websphere Application Server 7.0.0.13 IBM Websphere Application Server 7.0.0.1 IBM Websphere Application Server 7.0.0.0 IBM Websphere Application Server 6.1.0.39 IBM Websphere Application Server 6.1.0.35 IBM Websphere Application Server 6.1.0.34 IBM Websphere Application Server 6.1.0.33 IBM Websphere Application Server 6.1.0.33 IBM Websphere Application Server 6.1.0.31 IBM Websphere Application Server 6.1.0.29 IBM Websphere Application Server 6.1.0.27 IBM Websphere Application Server 6.1 IBM Websphere Application Server 6.0.2.43 IBM Websphere Application Server 6.0.2.41 IBM Websphere Application Server 6.0.2.19 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server Hash Collision Denial Of Service Vulnerability
IBM WebSphere Application Server is prone to a denial-of-service vulnerability.
An attacker can exploit this issue by sending specially crafted forms in HTTP POST requests.
IBM WebSphere Application Server versions 6.1.0.41 and prior, 7.0.0.21 and prior, and 8.0.0.2 and prior are affected.
IBM WebSphere Application Server is prone to a denial-of-service vulnerability.
An attacker can exploit this issue by sending specially crafted forms in HTTP POST requests.
IBM WebSphere Application Server versions 6.1.0.41 and prior, 7.0.0.21 and prior, and 8.0.0.2 and prior are affected.
Exploit / POC
IBM WebSphere Application Server Hash Collision Denial Of Service Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
IBM WebSphere Application Server Hash Collision Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM WebSphere Application Server Hash Collision Denial Of Service Vulnerability
References:
References: