CVE-2010-2328: Medium severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
Published Jun 18, 2010
·Updated
The HTTP Channel in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (NullPointerException) via a large amount of chunked data that uses gzip compression.
Affected Software
6 affected components
IBM WebSphere Application Server Feature Pack for Web Services=7.0
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.1
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.3
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.5
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.7
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.9
Remediation
Patch Available
Event History
Jun 18, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2328?
CVE-2010-2328 has a medium severity rating due to its potential for denial of service attacks.
2
What versions of IBM WebSphere Application Server are affected by CVE-2010-2328?
CVE-2010-2328 affects IBM WebSphere Application Server versions 7.0.0.1 to 7.0.0.9.
3
How do I fix CVE-2010-2328?
To fix CVE-2010-2328, upgrade IBM WebSphere Application Server to version 7.0.0.11 or later.
4
What is the exploit type for CVE-2010-2328?
CVE-2010-2328 is an exploit that can cause a denial of service through a NullPointerException.
5
What type of attack does CVE-2010-2328 facilitate?
CVE-2010-2328 facilitates remote denial of service attacks by sending a large amount of chunked gzip-compressed data.