Short Name |
HTTP:WEBSPHERE:VER-DOS |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
HTTP |
Keywords |
IBM WebSphere Edge Server Caching Proxy DoS |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against the caching proxy in IBM WebSphere Edge Server. Version 2.0 is vulnerable. Attachers can send a maliciously crafted HTTP GET request that does not have a proper version identifier to crash the proxy service and render the proxy unusable.
A vulnerability has been reported in the Caching Proxy component bundled with IBM WebSphere Edge Server. The vulnerability is due to inadequate checks when processing HTTP headers. An attacker can exploit this vulnerability by sending a malformed HTTP request to the Caching Proxy. When the service attempts to process the request the service will crash thereby causing the denial of service.