CVE-2011-1317: Medium severity ibm websphere application server feature pack for web services vulnerability
Memory leak in com.ibm.ws.jsp.runtime.WASJSPStrBufferImpl in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by sending many JSP requests that trigger large responses.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1317?
CVE-2011-1317 has a severity rating indicating a potential denial of service risk due to memory consumption.
How do I fix CVE-2011-1317?
To address CVE-2011-1317, upgrade to IBM WebSphere Application Server version 6.1.0.37 or later for 6.1.x and 7.0.0.15 or later for 7.x.
What are the affected versions for CVE-2011-1317?
CVE-2011-1317 affects IBM WebSphere Application Server versions 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15.
Can CVE-2011-1317 be exploited remotely?
Yes, CVE-2011-1317 can be exploited remotely by sending multiple JSP requests to the affected server.
What type of vulnerability is CVE-2011-1317?
CVE-2011-1317 is classified as a memory leak vulnerability in the JavaServer Pages component.