A buffer overflow vulnerability has been reported for IBM WebSphere 4.0.3 running on a Microsoft Windows 2000 platform. IBM WebSphere does not properly perform bounds checking when receiving HTTP requests. Specifically, the vulnerability is related to the WebSphere plugin not limiting the size of HTTP POST data that would be received by the application server. The application server will crash when it receives an overly large HTTP POST request.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.