CVE-2009-0433
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allows attackers to cause a denial of service (daemon…
Does this matter?
Lower severity and a low EPSS score (1.64%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allows attackers to cause a denial of service (daemon crash) via unknown vectors, related to a mishandling of client read failures in which clients receive many 500 HTTP error responses and backend servers are incorrectly labeled as down.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- ibm/websphere application server
- Source
- cve@mitre.org
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK67161
- http://www-01.ibm.com/support/docview.wss?uid=swg27006879Patch
- http://www-01.ibm.com/support/docview.wss?uid=swg27007033Patch
- http://www-01.ibm.com/support/docview.wss?uid=swg27007951Patch
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK63499Patch
- http://www.securityfocus.com/bid/33700Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48523
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK67161
- http://www-01.ibm.com/support/docview.wss?uid=swg27006879Patch
- http://www-01.ibm.com/support/docview.wss?uid=swg27007033Patch
- http://www-01.ibm.com/support/docview.wss?uid=swg27007951Patch
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK63499Patch
- http://www.securityfocus.com/bid/33700Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48523
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.