CVE-2012-5953: Buffer Overflow
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2, when the Parse Query Strings option is enabled on an HTTPInput node, allows remote attackers to cause a denial of service (infinite loop) via a crafted query string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5953?
CVE-2012-5953 has a critical severity rating as it can lead to denial of service.
How do I fix CVE-2012-5953?
To fix CVE-2012-5953, apply the latest security update for your version of IBM WebSphere Message Broker.
What software versions are affected by CVE-2012-5953?
CVE-2012-5953 affects IBM WebSphere Message Broker versions 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2.
What is the impact of exploiting CVE-2012-5953?
Exploiting CVE-2012-5953 allows remote attackers to cause an infinite loop resulting in denial of service.
Is there a workaround for CVE-2012-5953?
A possible workaround for CVE-2012-5953 is to disable the Parse Query Strings option on the HTTPInput node.