CVE-2008-4285: Medium severity ibm websphere application server feature pack for web services vulnerability
Unspecified vulnerability in the Performance Monitoring Infrastructure (PMI) feature in the Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19, when a component statistic is enabled, allows attackers to cause a denial of service (daemon crash) via vectors related to "a gradual degradation in performance."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4285?
CVE-2008-4285 is classified as a high severity vulnerability that can cause a denial of service.
How do I fix CVE-2008-4285?
To fix CVE-2008-4285, upgrade to IBM WebSphere Application Server version 6.1.0.19 or later.
What type of attack does CVE-2008-4285 facilitate?
CVE-2008-4285 facilitates denial of service attacks by causing a daemon crash when certain component statistics are enabled.
Which versions of IBM WebSphere Application Server are affected by CVE-2008-4285?
Versions of IBM WebSphere Application Server prior to 6.1.0.19, including 6.1.x versions, are affected by CVE-2008-4285.
Is there a workaround for CVE-2008-4285 if immediate patching is not possible?
As a temporary workaround for CVE-2008-4285, disabling the performance monitoring infrastructure may reduce the risk of exploitation.