CVE-2001-0390: Medium severity IBM Net.commerce Hosting Server vulnerability
Published May 24, 2001
·Updated
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
Affected Software
8 affected components
IBM Net.commerce Hosting Server=3.1.1
IBM Net.Commerce=3.1
IBM Net.Commerce=2.0
IBM Net.Commerce=3.0
IBM Net.Commerce=3.1.2
IBM Net.commerce Hosting Server=3.1.2
IBM WebSphere Application Server=5.1.0.3
IBM Net.Commerce=3.1.1
Event History
May 24, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0390?
CVE-2001-0390 is classified as a denial of service vulnerability.
2
How do I fix CVE-2001-0390?
To mitigate CVE-2001-0390, upgrade IBM Websphere or Net.Commerce to a version that is not vulnerable.
3
What systems are impacted by CVE-2001-0390?
CVE-2001-0390 affects IBM Net.Commerce versions 2.0, 3.0, 3.1, along with IBM Websphere Application Server version 5.1.0.3.
4
What causes the vulnerability in CVE-2001-0390?
CVE-2001-0390 is caused by the ability of remote attackers to call the macro.d2w macro with excessive %0a characters.
5
Is CVE-2001-0390 still a concern for current systems?
CVE-2001-0390 may no longer be a concern for systems using updated software, but it should still be monitored in legacy environments.