CVE-2000-0182: Medium severity iPlanet iPlanet Web Server vulnerability

Published Feb 23, 2000
·
Updated

iPlanet Web Server 4.1 allows remote attackers to cause a denial of service via a large number of GET commands, which consumes memory and causes a kernel panic.

Affected Software

1 affected component
iPlanet iPlanet Web Server=4.1_enterprise

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Sun iPlanet Web Server from your environment.

    Uninstall the Sun iPlanet Web Server if it is not required, or replace it with a supported alternative.

  2. Configuration

    Configure the web server or a front-end proxy/load balancer to limit the number of HTTP GET requests per client and to enforce global request-rate limits to prevent memory exhaustion from a large number of GET commands.

    Sun iPlanet Web Server HTTP GET rate limiting = limit excessive requests per client/IP
  3. Configuration

    Lower keepalive timeouts and reduce the maximum number of concurrent connections/requests to decrease memory usage under high request loads.

    Sun iPlanet Web Server keepalive timeout and max connections = reduce timeout and cap concurrent connections
  4. Compensating control

    Deploy a WAF, rate-limiting proxy, or perimeter firewall rules to detect, throttle, or block abusive patterns of repeated GET requests and restrict access to the server from untrusted networks.

  5. Operational

    Monitor server logs and network traffic for bursts of GET requests and anomalous client behavior; collect crash dumps and restart/recover servers that experience kernel panics. Coordinate with the vendor and apply any vendor-supplied patches when they become available.

Event History

Feb 23, 2000
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Apr 10, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2000-0182?

CVE-2000-0182 is classified as a high severity vulnerability due to its potential to cause a denial of service.

2

How do I fix CVE-2000-0182?

To fix CVE-2000-0182, it is recommended to upgrade to a newer version of iPlanet Web Server that is not affected by this vulnerability.

3

What systems are affected by CVE-2000-0182?

CVE-2000-0182 specifically affects iPlanet Web Server 4.1 Enterprise.

4

What type of attack does CVE-2000-0182 involve?

CVE-2000-0182 involves a denial of service attack that can be executed by sending a large number of GET commands.

5

What are the consequences of exploiting CVE-2000-0182?

Exploiting CVE-2000-0182 can lead to excessive memory consumption and subsequent kernel panic, resulting in service interruption.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203