CVE-2011-1313: Double Free
Double free vulnerability in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote backend IIOP servers to cause a denial of service (S0C4 ABEND and storage corruption) by rejecting IIOP requests at opportunistic time instants, as demonstrated by requests associated with an ORBRequest::getACRWorkElementPtr function call.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1313?
CVE-2011-1313 has a moderate severity rating due to the potential for denial of service and storage corruption.
How do I fix CVE-2011-1313?
To fix CVE-2011-1313, upgrade IBM WebSphere Application Server to version 6.1.0.35 or 7.0.0.15 or later.
What systems are affected by CVE-2011-1313?
CVE-2011-1313 affects IBM WebSphere Application Server versions 6.1.0.x prior to 6.1.0.35 and 7.x prior to 7.0.0.15.
What type of vulnerability is CVE-2011-1313?
CVE-2011-1313 is classified as a double free vulnerability that can lead to denial of service.
Is CVE-2011-1313 exploitative from the internet?
Yes, CVE-2011-1313 allows remote attackers to exploit the vulnerability by sending malformed IIOP requests.