IBM WebSphere Application Server Hash Collision Denial of Service Vulnerability
RISK: Medium Risk
TYPE: Servers - Internet App Servers
A vulnerability has been identified in IBM WebSphere Application Server, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error within a hash generation function when hashing form posts and updating a hash table. This can be exploited to cause a hash collision resulting in high CPU consumption via a specially crafted form sent in a HTTP POST request.
Impact
- Denial of Service
System / Technologies affected
- IBM WebSphere Application Server 6.1.x
- IBM WebSphere Application Server 7.0.x
- IBM WebSphere Application Server 8.0.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apply APAR PM53930
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with