Vulnerabilities > CVE-2008-4678 - Resource Management Errors vulnerability in IBM Websphere Application Server
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
COMPLETE Summary
The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure."
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | Web Servers |
NASL id | WEBSPHERE_6_0_2_31.NASL |
description | IBM WebSphere Application Server 6.0.2 before Fix Pack 31 appears to be running on the remote host. As such, it is reportedly affected by multiple vulnerabilities : - By sending a specially crafted HTTP request with the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 34501 |
published | 2008-10-27 |
reporter | This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/34501 |
title | IBM WebSphere Application Server < 6.0.2.31 Multiple Vulnerabilities |
code |
|
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 31839 CVE(CAN) ID: CVE-2008-4678,CVE-2008-4679 IBM Websphere应用服务器以Java和Servlet引擎为基础,支持多种HTTP服务,可帮助用户完成从开发、发布到维护交互式的动态网站的所有工作。 IBM WebSphere应用服务器的HTTP Transport组件中的HTTP_Request_Parser方式没有正确地验证用户所提交的HTTP请求。如果远程攻击者在请求中包含有超长的HTTP Host头的话,就可能导致拒绝服务(0C4控制器异常结束和应用程序挂起)。 如果将Certificate Store Collections配置为使用证书撤销列表(CRL)的话,WebSphere应用服务器的Web Services Security组件就没有对PKIXBuilderParameters对象调用setRevocationEnabled方式,导致Java安全方式无法检查X.509证书的撤销状态。远程攻击者可以通过发送带有已撤销证书的SOAP消息绕过预期的访问限制。 IBM Websphere Application Server 6.0.x IBM --- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href=http://www-01.ibm.com/support/docview.wss?uid=swg27007951 target=_blank>http://www-01.ibm.com/support/docview.wss?uid=swg27007951</a> <a href=http://www-01.ibm.com/support/docview.wss?uid=swg27006876 target=_blank>http://www-01.ibm.com/support/docview.wss?uid=swg27006876</a> |
id | SSV:4346 |
last seen | 2017-11-19 |
modified | 2008-10-27 |
published | 2008-10-27 |
reporter | Root |
title | IBM WebSphere应用服务器拒绝服务及绕过安全限制漏洞 |