IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
References
Link | Resource |
---|---|
http://osvdb.org/78321 | |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM53930 | |
http://www-01.ibm.com/support/docview.wss?uid=swg21577532 | Patch Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg24031821 | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ibm
Published: 2012-01-20T02:00:00
Updated: 2012-01-26T10:00:00
Reserved: 2011-12-14T00:00:00
Link: CVE-2012-0193
JSON object: View
NVD Information
Status : Modified
Published: 2012-01-20T04:04:51.607
Modified: 2012-01-27T04:04:23.157
Link: CVE-2012-0193
JSON object: View
Redhat Information
No data.
CWE