First published: Mon May 17 2010(Updated: )
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle chunked transfer encoding during a call to response.sendRedirect, which allows remote attackers to cause a denial of service via a GET request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =6.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.11 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.13 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.15 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.17 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.6 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.8 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.10 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.11 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.12 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.13 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.14 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.15 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.16 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.17 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.18 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.19 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.20 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.21 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.22 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.23 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.24 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.25 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.27 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.28 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.29 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.30 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.31 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.32 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.33 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.35 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.37 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.39 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.11 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.13 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.15 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.17 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.19 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.21 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.23 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.25 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.27 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.29 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0776 has a severity rating that indicates it may lead to a denial of service.
To fix CVE-2010-0776, upgrade your IBM WebSphere Application Server to version 6.0.2.43, 6.1.0.31, or 7.0.0.11 or later.
IBM WebSphere Application Server versions 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 are affected by CVE-2010-0776.
CVE-2010-0776 describes a vulnerability where the Web Container does not properly handle chunked transfer encoding during response redirection.
Remote attackers can exploit CVE-2010-0776 to cause a denial of service on affected IBM WebSphere Application Server instances.